CVE-2026-22367: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-22367 is a PHP Local File Inclusion (LFI) vulnerability in the AncoraThemes Coworking WordPress theme, affecting all versions through 1.6.1. The flaw stems from improper control of filenames used in PHP include/require statements (CWE-98), allowing unauthenticated remote attackers to include and execute arbitrary local files on the server. It was reported by Tran Nguyen Bao Khanh (VCI - VNPT Cyber Immunity) on November 30, 2025, and published on February 17–20, 2026. The vulnerability carries a CVSS v3.1 base score of 8.1 (High) (Patchstack, Feedly).

Technical details

The root cause is classified under CWE-98 (Improper Control of Filename for Include/Require Statement in PHP Program), where user-supplied input is passed unsanitized into a PHP include() or require() statement within the Coworking theme. An unauthenticated attacker can craft a network request that manipulates the filename parameter to traverse the file system and include sensitive local files. No user interaction is required, though attack complexity is rated High, suggesting some precondition such as specific server configuration or parameter guessing is needed. The vulnerability was identified by Patchstack with PSID 610880e304c3 and maps to CAPEC-193 (PHP Remote File Inclusion) (Patchstack).

Impact

Successful exploitation allows an attacker to read and potentially execute arbitrary local files on the web server, including sensitive configuration files such as wp-config.php that contain database credentials. This can lead to full database compromise, unauthorized disclosure of sensitive data, code execution, and denial of service. The vulnerability impacts confidentiality, integrity, and availability equally at a high level, and could serve as a foothold for broader lateral movement within a hosting environment (Patchstack).

Exploitability

As of the time of reporting, no public proof-of-concept exploit code exists and no active in-the-wild exploitation has been observed. The EPSS score is approximately 0.053% (0.000530), indicating a low current probability of exploitation. No CISA KEV catalog entry has been identified for this CVE. Patchstack notes that vulnerabilities of this class (LFI with CVSS 8.1) are frequently used in mass-exploit campaigns targeting WordPress sites regardless of traffic or popularity (Patchstack).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites using the AncoraThemes Coworking theme version 1.6.1 or earlier via tools like WPScan, Shodan, or by inspecting theme metadata in page source (/wp-content/themes/coworking/style.css).
  2. Identify vulnerable parameter: Analyze the theme's PHP source or observed HTTP requests to locate parameters passed to include() or require() statements without sanitization.
  3. Craft malicious request: Send an unauthenticated HTTP GET or POST request to the vulnerable endpoint with a manipulated filename parameter using path traversal sequences (e.g., ../../../../wp-config.php) to reference sensitive local files.
  4. Extract sensitive data: If successful, the server returns the contents of the included file (e.g., database credentials from wp-config.php) in the HTTP response.
  5. Escalate access: Use extracted credentials to access the WordPress database directly, enabling full site takeover, creation of admin accounts, or further lateral movement within the hosting environment (Patchstack).

Indicators of compromise

  • Network: Unusual HTTP requests to WordPress theme endpoints containing path traversal sequences (e.g., ../, ..%2F, %2e%2e%2f) in query parameters; repeated requests from a single IP to theme-related PHP files.
  • Logs: Web server access logs showing requests with encoded traversal patterns targeting Coworking theme endpoints; HTTP 200 responses to requests with suspicious filename parameters containing system file paths.
  • File System: Unexpected access to sensitive files such as wp-config.php, /etc/passwd, or other system files by the web server process; new or modified files in the theme directory.
  • Process: PHP process reading files outside the WordPress web root, particularly system configuration files or credential stores.

Mitigation and workarounds

No official patch from AncoraThemes is currently available for the Coworking theme. Patchstack has issued a virtual patching/mitigation rule to block exploitation attempts for users of its service. Recommended interim mitigations include: (1) deploying a Web Application Firewall (WAF) rule to detect and block path traversal and file inclusion payloads; (2) implementing strict input validation and allowlisting for any user-supplied parameters used in file operations; (3) restricting file system permissions so the web server process cannot read sensitive files outside the web root; and (4) considering removal or replacement of the theme until an official patch is released (Patchstack).

Community reactions

Wordfence included this vulnerability in its weekly WordPress vulnerability report covering February 16–22, 2026, indicating it received standard industry tracking attention. Patchstack classified it as high priority and issued a virtual mitigation rule, reflecting concern about the potential for mass exploitation of LFI vulnerabilities in WordPress themes. No notable individual researcher commentary or significant social media discussion has been identified beyond routine vulnerability database coverage.

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management