
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-22402 is a Local File Inclusion (LFI) vulnerability in the Triply WordPress theme developed by pavothemes. It stems from improper control of filename parameters used in PHP include/require statements (CWE-98), allowing authenticated attackers to include arbitrary local files. All versions of the Triply theme up to and including 2.4.7 are affected. The vulnerability was published on January 22, 2026, with a CVSS v3.1 base score of 7.5 (High), as assessed by CISA-ADP (Feedly, Patchstack).
The root cause is classified under CWE-98 (Improper Control of Filename for Include/Require Statement in PHP Program), commonly referred to as PHP Remote File Inclusion, though in this case the exploitation is limited to local file inclusion. The vulnerability arises when user-supplied input is passed unsanitized to PHP's include or require constructs within the Triply theme, enabling an attacker to manipulate the file path parameter to reference arbitrary files on the server. Exploitation requires low-level authenticated access (e.g., a subscriber or contributor account) and high attack complexity, suggesting some preconditions such as specific server configurations or parameter exposure must be met (Feedly, Patchstack).
Successful exploitation allows an attacker to read sensitive local files on the server (e.g., WordPress configuration files such as wp-config.php containing database credentials), and under certain conditions may enable remote code execution by including files with attacker-controlled content (e.g., uploaded image files containing PHP code). The CVSS assessment reflects high impacts to confidentiality, integrity, and availability, indicating that full system compromise is theoretically achievable. Exposure of database credentials could further enable lateral movement to backend databases or other connected systems (Feedly).
No public proof-of-concept exploit code or evidence of active in-the-wild exploitation has been identified for CVE-2026-22402 at this time. The EPSS score is approximately 0.053% (0.000530), indicating a low probability of exploitation in the near term. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported (Feedly).
../../../../wp-config.php) to reference sensitive local files.wp-config.php, which may contain database credentials, secret keys, and other sensitive configuration data.../, ..%2F, %2e%2e%2f) in query parameters or POST body fields associated with the Triply theme.wp-config.php./wp-content/uploads/) with .php extensions or double extensions (e.g., .php.jpg).curl, wget, bash) that may indicate post-exploitation activity following successful LFI-to-RCE escalation.Users of the Triply WordPress theme should update to a version beyond 2.4.7 as soon as a patched release is made available by pavothemes. In the interim, site administrators should restrict access to the WordPress admin and theme functionality to trusted IP addresses where possible, and disable user registration if not required to reduce the attack surface. Web application firewalls (WAFs) can be configured with rules to detect and block directory traversal patterns in HTTP requests. Monitoring web server logs for traversal sequences is also recommended as a detective control (Patchstack).
The vulnerability was reported by Patchstack, which assigned and disclosed the CVE on January 22, 2026. Wordfence referenced this vulnerability in their weekly WordPress vulnerability report covering the period of December 15, 2025 to January 4, 2026. No significant broader media coverage or notable researcher commentary beyond these standard disclosure channels has been identified (Wordfence, Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."