
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-22477 is a PHP Local File Inclusion (LFI) vulnerability in the AncoraThemes Felizia WordPress theme, classified under CWE-98 (Improper Control of Filename for Include/Require Statement in PHP Program). It affects all versions of the Felizia theme through 1.3.4. The vulnerability was published on March 5, 2026, with the CVE assigned by Patchstack. It carries a CVSS v3.1 base score of 8.1 (High) (Feedly, Patchstack).
The root cause is improper handling of user-controlled input passed to PHP file inclusion/require statements (CWE-98), allowing an attacker to manipulate the filename parameter to include arbitrary local files from the server filesystem. The attack vector is network-based, requires no authentication (no privileges required) and no user interaction, though the attack complexity is rated High, suggesting some precondition or bypass is needed to successfully exploit the flaw. An attacker who meets the exploitation conditions can cause the PHP interpreter to include and potentially execute arbitrary local files. No public proof-of-concept code has been identified at this time (Feedly).
Successful exploitation could allow an unauthenticated remote attacker to read sensitive files from the server filesystem (e.g., configuration files containing credentials) and potentially execute arbitrary code if writable or uploadable files can be included. The vulnerability has high impact across confidentiality, integrity, and availability, meaning a successful attack could result in full server compromise, data theft, and service disruption. Lateral movement within a hosting environment is also a risk if credentials or internal network details are exposed through file disclosure (Feedly).
There is currently no public proof-of-concept exploit and no evidence of in-the-wild exploitation for CVE-2026-22477. The EPSS score is approximately 0.053%, indicating a low probability of exploitation in the near term. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported (Feedly).
No official patch has been confirmed in the available vulnerability data for the Felizia theme beyond version 1.3.4. Site administrators should check the WordPress theme repository or AncoraThemes directly for an updated version and upgrade immediately if available. As interim mitigations, deploy a Web Application Firewall (WAF) with rules targeting file inclusion attempts (e.g., path traversal patterns like ../ or null bytes), restrict direct access to the theme directory, and monitor web server logs for anomalous file inclusion requests. Disabling or replacing the vulnerable theme until a patch is available is also advisable (Feedly).
Wordfence included CVE-2026-22477 in its weekly WordPress vulnerability report for the period of March 2–8, 2026, highlighting it as part of a broader set of theme-related vulnerabilities. No significant independent researcher commentary or major media coverage has been identified beyond standard vulnerability tracking and reporting (Wordfence).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."