
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-22367 is a PHP Local File Inclusion (LFI) vulnerability in the AncoraThemes Coworking WordPress theme, affecting all versions through 1.6.1. The flaw stems from improper control of filenames used in PHP include/require statements (CWE-98), allowing unauthenticated remote attackers to include and execute arbitrary local files on the server. It was reported by Tran Nguyen Bao Khanh (VCI - VNPT Cyber Immunity) on November 30, 2025, and published on February 17–20, 2026. The vulnerability carries a CVSS v3.1 base score of 8.1 (High) (Patchstack, Feedly).
The root cause is classified under CWE-98 (Improper Control of Filename for Include/Require Statement in PHP Program), where user-supplied input is passed unsanitized into a PHP include() or require() statement within the Coworking theme. An unauthenticated attacker can craft a network request that manipulates the filename parameter to traverse the file system and include sensitive local files. No user interaction is required, though attack complexity is rated High, suggesting some precondition such as specific server configuration or parameter guessing is needed. The vulnerability was identified by Patchstack with PSID 610880e304c3 and maps to CAPEC-193 (PHP Remote File Inclusion) (Patchstack).
Successful exploitation allows an attacker to read and potentially execute arbitrary local files on the web server, including sensitive configuration files such as wp-config.php that contain database credentials. This can lead to full database compromise, unauthorized disclosure of sensitive data, code execution, and denial of service. The vulnerability impacts confidentiality, integrity, and availability equally at a high level, and could serve as a foothold for broader lateral movement within a hosting environment (Patchstack).
As of the time of reporting, no public proof-of-concept exploit code exists and no active in-the-wild exploitation has been observed. The EPSS score is approximately 0.053% (0.000530), indicating a low current probability of exploitation. No CISA KEV catalog entry has been identified for this CVE. Patchstack notes that vulnerabilities of this class (LFI with CVSS 8.1) are frequently used in mass-exploit campaigns targeting WordPress sites regardless of traffic or popularity (Patchstack).
/wp-content/themes/coworking/style.css).include() or require() statements without sanitization.../../../../wp-config.php) to reference sensitive local files.wp-config.php) in the HTTP response.../, ..%2F, %2e%2e%2f) in query parameters; repeated requests from a single IP to theme-related PHP files.wp-config.php, /etc/passwd, or other system files by the web server process; new or modified files in the theme directory.No official patch from AncoraThemes is currently available for the Coworking theme. Patchstack has issued a virtual patching/mitigation rule to block exploitation attempts for users of its service. Recommended interim mitigations include: (1) deploying a Web Application Firewall (WAF) rule to detect and block path traversal and file inclusion payloads; (2) implementing strict input validation and allowlisting for any user-supplied parameters used in file operations; (3) restricting file system permissions so the web server process cannot read sensitive files outside the web root; and (4) considering removal or replacement of the theme until an official patch is released (Patchstack).
Wordfence included this vulnerability in its weekly WordPress vulnerability report covering February 16–22, 2026, indicating it received standard industry tracking attention. Patchstack classified it as high priority and issued a virtual mitigation rule, reflecting concern about the potential for mass exploitation of LFI vulnerabilities in WordPress themes. No notable individual researcher commentary or significant social media discussion has been identified beyond routine vulnerability database coverage.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."