CVE-2026-27383: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-27383 is a PHP Local File Inclusion (LFI) vulnerability in the RadiusTheme Metro WordPress theme, classified under CWE-98 (Improper Control of Filename for Include/Require Statement in PHP Program). It affects Metro versions up to and including 2.13, allowing remote attackers to include arbitrary local files without authentication. The vulnerability was published on March 5, 2026, with CVSSv3.1 base score of 8.1 (High) (Feedly, Patchstack).

Technical details

The root cause is improper control of filenames used in PHP include/require statements (CWE-98), which enables PHP Local File Inclusion. An attacker can supply a crafted input over the network to manipulate the file path passed to a PHP include/require call, causing the server to load arbitrary local files. Exploitation requires no authentication, no user interaction, and no special privileges, though attack complexity is rated High, suggesting some precondition or bypass is needed (e.g., specific server configuration or parameter guessing). The vulnerability was reported and assigned by Patchstack (Feedly, Patchstack).

Impact

Successful exploitation can lead to complete compromise of the affected WordPress server's confidentiality, integrity, and availability. An attacker could read sensitive files (e.g., wp-config.php, /etc/passwd), potentially expose database credentials, and — if combined with a file upload or log poisoning technique — achieve remote code execution. The scope is limited to the affected system, but credential exposure could enable lateral movement to connected databases or infrastructure (Feedly).

Exploitability

As of the time of reporting, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (Feedly). The EPSS score is approximately 0.053%, indicating a low current probability of exploitation. No threat actor attribution has been made, and the vulnerability does not appear in the CISA Known Exploited Vulnerabilities (KEV) catalog.

Exploitation steps

  1. Reconnaissance: Identify WordPress sites using the RadiusTheme Metro theme version ≤ 2.13 via passive scanning tools (e.g., WPScan, Shodan) or by inspecting theme metadata in publicly accessible style.css files.
  2. Identify vulnerable parameter: Locate the theme's PHP file inclusion point — a parameter or request value that is passed unsanitized to a PHP include() or require() statement within the Metro theme code.
  3. Craft malicious request: Send a crafted HTTP request (GET or POST) to the vulnerable endpoint with a manipulated filename parameter pointing to a sensitive local file, such as ../../../../wp-config.php or /etc/passwd.
  4. Extract sensitive data: Review the server's HTTP response for the contents of the included file, which may expose database credentials, secret keys, or system user information.
  5. Escalate (optional): If the server logs user-controlled input (e.g., User-Agent) to an accessible log file, inject PHP code into the log and then include that log file via the LFI to achieve remote code execution (Feedly).

Indicators of compromise

  • Network: Unusual HTTP requests to Metro theme endpoints containing path traversal sequences (e.g., ../, ..%2F, %2e%2e%2f) in query parameters or POST body fields.
  • Logs: WordPress or web server access logs showing requests with encoded traversal patterns targeting theme PHP files; repeated 200 responses to requests with file path parameters pointing to system files.
  • File System: Unexpected access to sensitive files such as wp-config.php, /etc/passwd, or PHP session files by the web server process; new or modified PHP files in the theme directory.
  • Process: Web server process (e.g., apache2, nginx, php-fpm) spawning unexpected child processes if code execution was achieved via log poisoning or similar chaining technique.

Mitigation and workarounds

Users should update the RadiusTheme Metro WordPress theme to a version newer than 2.13 as soon as a patched release becomes available; no specific patched version number has been confirmed in available data (Feedly, Patchstack). In the interim, implement Web Application Firewall (WAF) rules to detect and block path traversal and LFI patterns in HTTP requests. Restrict PHP file system permissions to limit which files the web server process can read, and enforce input validation with allowlist controls for any file inclusion operations. Monitor application logs for suspicious file inclusion attempts.

Community reactions

Wordfence noted this vulnerability in their weekly WordPress vulnerability report covering the period of February 23 – March 1, 2026 (Wordfence). No significant broader media coverage or notable researcher commentary beyond standard vulnerability database entries has been identified.

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management