
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-22478 is a PHP Local File Inclusion (LFI) vulnerability in the Elated-Themes FindAll WordPress theme, classified under CWE-98 (Improper Control of Filename for Include/Require Statement in PHP Program). It affects all versions of the FindAll theme up to and including version 1.4. The vulnerability was published on March 5, 2026, and assigned by Patchstack. It carries a CVSS v3.1 base score of 8.1 (High) (Feedly, EUVD).
The root cause is improper control of filename parameters used in PHP include/require statements within the FindAll theme (CWE-98), which allows an attacker to manipulate file path inputs to include arbitrary local files on the server. The attack vector is network-based, requires no authentication or user interaction, but has high attack complexity, suggesting specific conditions or knowledge are needed to exploit it. No public proof-of-concept code has been identified at this time (Feedly, Patchstack).
Successful exploitation of this LFI vulnerability could allow an unauthenticated remote attacker to read sensitive local files such as configuration files, database credentials, and system files, leading to a full compromise of confidentiality, integrity, and availability. An attacker could leverage exposed credentials for lateral movement within the hosting environment or escalate to remote code execution if file upload functionality or other writable paths are accessible. The CVSS scoring reflects high impact across all three security pillars (Feedly).
As of the time of reporting, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation. The vulnerability has an EPSS score of approximately 0.053%, indicating a low but non-zero probability of exploitation in the near term. It has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. No specific threat actor attribution has been made (Feedly).
No official patch has been released for the FindAll theme beyond version 1.4 as of the disclosure date. Users should consider deactivating or removing the FindAll theme until a patched version is available. In the interim, implement strict input validation and allowlisting for filename parameters in PHP include/require statements, deploy Web Application Firewall (WAF) rules to detect and block LFI exploitation attempts, and monitor server logs for suspicious file inclusion requests (Feedly, Patchstack).
The vulnerability was noted in the Wordfence Intelligence Weekly WordPress Vulnerability Report for the week of March 2–8, 2026, which aggregates newly disclosed WordPress theme and plugin vulnerabilities. No significant independent researcher commentary or broader media coverage has been identified beyond standard vulnerability tracking (Wordfence Blog).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."