
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-22410 is a PHP Local File Inclusion (LFI) vulnerability in the Mikado-Themes Dolcino WordPress theme, classified under CWE-98 (Improper Control of Filename for Include/Require Statement in PHP Program). It affects all versions of the Dolcino theme up to and including version 1.6. The vulnerability was published on March 5, 2026, with the CVE assigned by Patchstack. It carries a CVSS v3.1 base score of 8.1 (High) (Feedly, Patchstack).
The root cause is improper control of filenames used in PHP include/require statements within the Dolcino theme (CWE-98), which allows attacker-controlled input to influence which files are included by the PHP interpreter. An unauthenticated remote attacker can craft a network-based request that manipulates the file path parameter, causing the server to include arbitrary local files. No user interaction or authentication is required, though the attack complexity is rated High, suggesting some precondition or bypass technique is needed to reliably trigger the inclusion. The vulnerability is mapped to CAPEC-193 (PHP Remote File Inclusion) (Feedly).
Successful exploitation allows an attacker to read sensitive files on the server (e.g., configuration files containing database credentials, WordPress wp-config.php), execute malicious code by including attacker-controlled content, and potentially achieve full system compromise. The CVSS scoring reflects high impact across confidentiality, integrity, and availability, meaning an attacker could exfiltrate sensitive data, modify site content, or disrupt service availability. In a shared hosting environment, exploitation could also facilitate lateral movement to other hosted sites or services (Feedly).
As of the time of reporting, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (Feedly). The EPSS score is approximately 0.053%, indicating a low current probability of exploitation in the near term. No threat actor attribution has been made, and the vulnerability does not appear in the CISA Known Exploited Vulnerabilities (KEV) catalog. The High attack complexity rating further reduces the immediate risk of opportunistic exploitation.
style.css files.include/require statements.../../../../wp-config.php) or a previously uploaded malicious file.../, ..%2F, %2e%2e%2f) in query parameters or POST body fields targeting the Dolcino theme endpoints./etc/passwd, wp-config.php) in theme-related URLs.No official patch for the Dolcino theme (version ≤ 1.6) has been confirmed as available at the time of disclosure (Feedly). Immediate recommended actions include: disabling or removing the Dolcino theme until a patched version is released; deploying a Web Application Firewall (WAF) with rules to block path traversal and file inclusion attempts; implementing server-side open_basedir restrictions in PHP to limit accessible file paths; and monitoring web server logs for path traversal patterns. Site administrators should check the Patchstack database and the theme's official repository for patch availability (Patchstack).
Wordfence noted this vulnerability in their weekly WordPress vulnerability report covering the period of February 23 to March 1, 2026, highlighting it as part of a broader set of WordPress theme and plugin vulnerabilities (Wordfence). VulDB also indexed the vulnerability shortly after disclosure. No significant independent researcher commentary or broader media coverage has been identified beyond standard vulnerability database entries.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."