CVE-2026-22410: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-22410 is a PHP Local File Inclusion (LFI) vulnerability in the Mikado-Themes Dolcino WordPress theme, classified under CWE-98 (Improper Control of Filename for Include/Require Statement in PHP Program). It affects all versions of the Dolcino theme up to and including version 1.6. The vulnerability was published on March 5, 2026, with the CVE assigned by Patchstack. It carries a CVSS v3.1 base score of 8.1 (High) (Feedly, Patchstack).

Technical details

The root cause is improper control of filenames used in PHP include/require statements within the Dolcino theme (CWE-98), which allows attacker-controlled input to influence which files are included by the PHP interpreter. An unauthenticated remote attacker can craft a network-based request that manipulates the file path parameter, causing the server to include arbitrary local files. No user interaction or authentication is required, though the attack complexity is rated High, suggesting some precondition or bypass technique is needed to reliably trigger the inclusion. The vulnerability is mapped to CAPEC-193 (PHP Remote File Inclusion) (Feedly).

Impact

Successful exploitation allows an attacker to read sensitive files on the server (e.g., configuration files containing database credentials, WordPress wp-config.php), execute malicious code by including attacker-controlled content, and potentially achieve full system compromise. The CVSS scoring reflects high impact across confidentiality, integrity, and availability, meaning an attacker could exfiltrate sensitive data, modify site content, or disrupt service availability. In a shared hosting environment, exploitation could also facilitate lateral movement to other hosted sites or services (Feedly).

Exploitability

As of the time of reporting, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (Feedly). The EPSS score is approximately 0.053%, indicating a low current probability of exploitation in the near term. No threat actor attribution has been made, and the vulnerability does not appear in the CISA Known Exploited Vulnerabilities (KEV) catalog. The High attack complexity rating further reduces the immediate risk of opportunistic exploitation.

Exploitation steps

  1. Reconnaissance: Identify WordPress sites using the Dolcino theme (version ≤ 1.6) via passive scanning tools (e.g., WPScan, Shodan) or by inspecting theme metadata in publicly accessible style.css files.
  2. Identify vulnerable parameter: Analyze the theme's PHP source code or observed HTTP requests to locate parameters that are passed unsanitized to PHP include/require statements.
  3. Craft malicious request: Construct an HTTP request that manipulates the vulnerable file path parameter to reference a sensitive local file (e.g., ../../../../wp-config.php) or a previously uploaded malicious file.
  4. Trigger file inclusion: Send the crafted request to the target WordPress site, causing the server to include and execute or return the contents of the targeted file.
  5. Achieve objective: Extract sensitive data (credentials, API keys) from included configuration files, or leverage included malicious content to establish a web shell for persistent access (Feedly).

Indicators of compromise

  • Network: HTTP requests containing path traversal sequences (e.g., ../, ..%2F, %2e%2e%2f) in query parameters or POST body fields targeting the Dolcino theme endpoints.
  • Logs: WordPress or web server access logs showing unusual GET/POST requests with file path patterns referencing system files (e.g., /etc/passwd, wp-config.php) in theme-related URLs.
  • File System: Unexpected new PHP files or web shells in the WordPress uploads directory or theme directory; modification timestamps on theme files inconsistent with legitimate updates.
  • Process: Unusual PHP child processes spawning system commands or making outbound network connections from the web server process.

Mitigation and workarounds

No official patch for the Dolcino theme (version ≤ 1.6) has been confirmed as available at the time of disclosure (Feedly). Immediate recommended actions include: disabling or removing the Dolcino theme until a patched version is released; deploying a Web Application Firewall (WAF) with rules to block path traversal and file inclusion attempts; implementing server-side open_basedir restrictions in PHP to limit accessible file paths; and monitoring web server logs for path traversal patterns. Site administrators should check the Patchstack database and the theme's official repository for patch availability (Patchstack).

Community reactions

Wordfence noted this vulnerability in their weekly WordPress vulnerability report covering the period of February 23 to March 1, 2026, highlighting it as part of a broader set of WordPress theme and plugin vulnerabilities (Wordfence). VulDB also indexed the vulnerability shortly after disclosure. No significant independent researcher commentary or broader media coverage has been identified beyond standard vulnerability database entries.

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management