
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-27383 is a PHP Local File Inclusion (LFI) vulnerability in the RadiusTheme Metro WordPress theme, classified under CWE-98 (Improper Control of Filename for Include/Require Statement in PHP Program). It affects Metro versions up to and including 2.13, allowing remote attackers to include arbitrary local files without authentication. The vulnerability was published on March 5, 2026, with CVSSv3.1 base score of 8.1 (High) (Feedly, Patchstack).
The root cause is improper control of filenames used in PHP include/require statements (CWE-98), which enables PHP Local File Inclusion. An attacker can supply a crafted input over the network to manipulate the file path passed to a PHP include/require call, causing the server to load arbitrary local files. Exploitation requires no authentication, no user interaction, and no special privileges, though attack complexity is rated High, suggesting some precondition or bypass is needed (e.g., specific server configuration or parameter guessing). The vulnerability was reported and assigned by Patchstack (Feedly, Patchstack).
Successful exploitation can lead to complete compromise of the affected WordPress server's confidentiality, integrity, and availability. An attacker could read sensitive files (e.g., wp-config.php, /etc/passwd), potentially expose database credentials, and — if combined with a file upload or log poisoning technique — achieve remote code execution. The scope is limited to the affected system, but credential exposure could enable lateral movement to connected databases or infrastructure (Feedly).
As of the time of reporting, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (Feedly). The EPSS score is approximately 0.053%, indicating a low current probability of exploitation. No threat actor attribution has been made, and the vulnerability does not appear in the CISA Known Exploited Vulnerabilities (KEV) catalog.
style.css files.include() or require() statement within the Metro theme code.../../../../wp-config.php or /etc/passwd.../, ..%2F, %2e%2e%2f) in query parameters or POST body fields.wp-config.php, /etc/passwd, or PHP session files by the web server process; new or modified PHP files in the theme directory.apache2, nginx, php-fpm) spawning unexpected child processes if code execution was achieved via log poisoning or similar chaining technique.Users should update the RadiusTheme Metro WordPress theme to a version newer than 2.13 as soon as a patched release becomes available; no specific patched version number has been confirmed in available data (Feedly, Patchstack). In the interim, implement Web Application Firewall (WAF) rules to detect and block path traversal and LFI patterns in HTTP requests. Restrict PHP file system permissions to limit which files the web server process can read, and enforce input validation with allowlist controls for any file inclusion operations. Monitor application logs for suspicious file inclusion attempts.
Wordfence noted this vulnerability in their weekly WordPress vulnerability report covering the period of February 23 – March 1, 2026 (Wordfence). No significant broader media coverage or notable researcher commentary beyond standard vulnerability database entries has been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."