CVE-2026-22478
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-22478 is a PHP Local File Inclusion (LFI) vulnerability in the Elated-Themes FindAll WordPress theme, classified under CWE-98 (Improper Control of Filename for Include/Require Statement in PHP Program). It affects all versions of the FindAll theme up to and including version 1.4. The vulnerability was published on March 5, 2026, and assigned by Patchstack. It carries a CVSS v3.1 base score of 8.1 (High) (Feedly, EUVD).

Technical details

The root cause is improper control of filename parameters used in PHP include/require statements within the FindAll theme (CWE-98), which allows an attacker to manipulate file path inputs to include arbitrary local files on the server. The attack vector is network-based, requires no authentication or user interaction, but has high attack complexity, suggesting specific conditions or knowledge are needed to exploit it. No public proof-of-concept code has been identified at this time (Feedly, Patchstack).

Impact

Successful exploitation of this LFI vulnerability could allow an unauthenticated remote attacker to read sensitive local files such as configuration files, database credentials, and system files, leading to a full compromise of confidentiality, integrity, and availability. An attacker could leverage exposed credentials for lateral movement within the hosting environment or escalate to remote code execution if file upload functionality or other writable paths are accessible. The CVSS scoring reflects high impact across all three security pillars (Feedly).

Exploitability

As of the time of reporting, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation. The vulnerability has an EPSS score of approximately 0.053%, indicating a low but non-zero probability of exploitation in the near term. It has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. No specific threat actor attribution has been made (Feedly).

Mitigation and workarounds

No official patch has been released for the FindAll theme beyond version 1.4 as of the disclosure date. Users should consider deactivating or removing the FindAll theme until a patched version is available. In the interim, implement strict input validation and allowlisting for filename parameters in PHP include/require statements, deploy Web Application Firewall (WAF) rules to detect and block LFI exploitation attempts, and monitor server logs for suspicious file inclusion requests (Feedly, Patchstack).

Community reactions

The vulnerability was noted in the Wordfence Intelligence Weekly WordPress Vulnerability Report for the week of March 2–8, 2026, which aggregates newly disclosed WordPress theme and plugin vulnerabilities. No significant independent researcher commentary or broader media coverage has been identified beyond standard vulnerability tracking (Wordfence Blog).

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-82923CRITICAL9.8
  • gw-website-builder-main
NoNoSep 04, 2026
CVE-2026-12483HIGH7.5
  • sfwd-lms
NoYesSep 04, 2026
CVE-2026-84045MEDIUM5.3
  • ecab-taxi-booking-manager
NoYesSep 04, 2026
CVE-2026-84044MEDIUM5.3
  • mp-restaurant-menu
NoYesSep 04, 2026
CVE-2026-84043MEDIUM5.3
  • epayco-gateway
NoYesSep 04, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management