
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-22401 is a PHP Local File Inclusion (LFI) vulnerability in the Freshio WordPress theme developed by pavothemes. The flaw stems from improper control of filename parameters used in PHP include/require statements (CWE-98), allowing authenticated attackers to include arbitrary local files on the server. It affects Freshio versions from the initial release through 2.4.2. The vulnerability was published on January 22, 2026, and carries a CVSS v3.1 base score of 7.5 (High) (Feedly).
The vulnerability is classified under CWE-98 (Improper Control of Filename for Include/Require Statement in PHP Program), commonly associated with PHP Remote/Local File Inclusion attacks (CAPEC-193). The attack is delivered over the network and requires low-level privileges (authenticated access), but no user interaction. An attacker can manipulate a filename parameter passed to a PHP include() or require() statement within the Freshio theme, causing the server to include unintended local files — potentially exposing sensitive configuration files or enabling code execution if combined with file upload capabilities (Feedly, Wordfence).
Successful exploitation can result in high confidentiality, integrity, and availability impacts on the affected WordPress installation. An attacker could read sensitive local files such as wp-config.php (exposing database credentials), server configuration files, or other sensitive data. In scenarios where file upload is possible, LFI can be chained to achieve remote code execution, potentially leading to full site compromise and lateral movement within the hosting environment (Feedly).
The vulnerability requires low-level authenticated access and high attack complexity, limiting opportunistic exploitation. No public proof-of-concept exploit code or evidence of active in-the-wild exploitation has been reported at this time. The EPSS score is approximately 0.053%, indicating a low probability of exploitation in the near term. CVE-2026-22401 does not appear in the CISA Known Exploited Vulnerabilities (KEV) catalog (Feedly).
include() or require() call within the Freshio theme codebase.../../../../wp-config.php) to trigger inclusion of a sensitive local file.wp-config.php) or, if file upload is available, chain LFI with an uploaded PHP file to achieve remote code execution (Feedly).../, %2e%2e%2f, or absolute paths like /etc/passwd).include()/require() calls with unexpected file paths.wp-config.php, /etc/passwd, or server configuration files coinciding with suspicious web requests.Users should update the Freshio WordPress theme to a version beyond 2.4.2 as soon as a patched release is made available by pavothemes. In the interim, site administrators should restrict access to the WordPress admin and subscriber registration features to limit the attacker's ability to obtain the required low-privilege credentials. Web application firewalls (WAFs) with rules targeting path traversal and LFI patterns can provide additional protection. Monitor the Patchstack database and the WordPress theme repository for patch availability (Wordfence, Feedly).
Wordfence included CVE-2026-22401 in its weekly WordPress vulnerability report covering December 15, 2025 to January 4, 2026, highlighting it as part of a broader set of theme-related vulnerabilities (Wordfence). No significant independent researcher commentary or broader media coverage has been identified beyond standard vulnerability database listings.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."