HIGHCVSS 8.1Vulnerability

CVE-2026-78478

The Mane theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.7. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.

Properties

severity
HIGH
cvss_severity
HIGH
cvss_score
8.1
retrieved_at
2026-09-29T00:56:27+00:00
score
8.1
last_source
NVD
cve_id
CVE-2026-78478
cvss_vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
signal_observed_at
2026-09-29T00:56:27+00:00
vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
published_at
2026-08-25T06:19:01.353
last_modified
2026-09-28T23:10:00.143

Related Entities (2)

HAS_WEAKNESS (1)

→[Weakness]Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')

DESCRIBED_BY (1)

→[Source]NVD

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-78478 (CVSS 8.1) — Ninja Signal Threat Intelligence | Ninja Signal