
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-22326 is an unauthenticated Local File Inclusion (LFI) vulnerability affecting the Reprizo WordPress theme by AxiomThemes in versions 1.0.8 and earlier. Discovered by Tran Nguyen Bao Khanh (VCI - VNPT Cyber Immunity) on September 16, 2025, and published by Patchstack on January 12, 2026, the vulnerability has a CVSS v3.1 base score of 8.1 (High). As of the time of reporting, no official patch from the vendor is available (Patchstack).
The vulnerability is classified as CWE-98 (Improper Control of Filename for Include/Require Statement in PHP Program), which maps to PHP Remote File Inclusion/Local File Inclusion weaknesses. An unauthenticated remote attacker can manipulate file path parameters in the Reprizo theme to cause the PHP application to include arbitrary local files from the server's filesystem. No authentication or user interaction is required, though the attack complexity is rated High, suggesting some precondition or non-trivial exploitation step is involved. The vulnerability is associated with CAPEC-193 (PHP Remote File Inclusion) (Patchstack).
Successful exploitation allows an unauthenticated attacker to read arbitrary local files on the web server, including sensitive configuration files such as wp-config.php, which contains database credentials. This could lead to complete database takeover, exposure of secret keys, and further compromise of the WordPress installation. The confidentiality, integrity, and availability impacts are all rated High, indicating potential for full system compromise (Patchstack).
/wp-content/themes/reprizo/).include() or require() call.../../../../wp-config.php or /etc/passwd, injected into the vulnerable parameter.../, ..%2F, ....//) in query parameters; requests returning contents of system files such as /etc/passwd or wp-config.php./wp-content/uploads/).wp-config.php are used for unauthorized access.As of the disclosure date, no official patch from AxiomThemes is available for the Reprizo theme. Patchstack has issued a virtual patching/mitigation rule for its subscribers to block exploitation attempts until an official fix is released. Site owners are advised to deactivate and remove the Reprizo theme if possible, or contact their hosting provider for assistance. Alternatively, deploying a Web Application Firewall (WAF) with rules targeting LFI/path traversal patterns can reduce exposure (Patchstack).
Wordfence included this vulnerability in their weekly WordPress vulnerability report for January 12–18, 2026, indicating broader community awareness within the WordPress security ecosystem. Patchstack, the assigning CNA, classified the vulnerability as high priority and noted its potential for use in mass-exploit campaigns. No significant vendor statement from AxiomThemes has been publicly issued.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."