
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-27986 is a Local File Inclusion (LFI) vulnerability in the ThemeREX OsTende WordPress theme, classified under CWE-98 (Improper Control of Filename for Include/Require Statement in PHP Program). It affects OsTende versions up to and including 1.4.3, and was published on March 2–5, 2026, with discovery credited to researcher "Bonds" and disclosure coordinated by Patchstack. The vulnerability carries a CVSS v3.1 base score of 8.1 (High), exploitable remotely without authentication or user interaction (Patchstack).
The root cause is improper validation of filename parameters passed to PHP include/require statements within the OsTende theme (CWE-98), allowing an attacker to manipulate the file path and cause the server to include arbitrary local files. The attack vector is network-based, requires no privileges or user interaction, but is classified as high complexity. An unauthenticated remote attacker can craft a malicious HTTP request with a manipulated filename parameter to trigger inclusion of sensitive server-side files such as configuration files containing database credentials (Patchstack).
Successful exploitation allows an unauthenticated attacker to read arbitrary local files on the web server, potentially exposing sensitive data such as WordPress configuration files (wp-config.php) containing database credentials, which could lead to full database compromise. The vulnerability also poses risks to integrity and availability, as file inclusion can in some configurations enable code execution. The scope is limited to the affected system, but credential exposure could facilitate lateral movement to connected database servers (Patchstack).
As of the time of disclosure, no public proof-of-concept exploit code has been identified, and there is no evidence of active in-the-wild exploitation. The EPSS score is approximately 0.053% (0.000530), indicating a currently low probability of exploitation in the near term. No threat actor attribution has been made, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Patchstack notes that vulnerabilities of this class (LFI with no authentication required) are frequently used in mass-exploit campaigns targeting WordPress sites (Patchstack).
style.css files.include/require statement.../../../../wp-config.php) into the filename parameter.wp-config.php exposing database credentials).../, ..%2F, ....//) in query parameters or POST body fields targeting OsTende theme endpoints.%2e%2e%2f, ..%2f) and HTTP 200 responses to unexpected file paths; requests returning contents of wp-config.php or /etc/passwd.wp-config.php, /etc/passwd) via server-side logging or file integrity monitoring.No official patch from ThemeREX is currently available; the theme has not been updated in over a year and is unlikely to receive further updates. Patchstack has issued a virtual patching/mitigation rule for its subscribers to block exploitation attempts until an official fix is available. The recommended remediation steps are: (1) remove and replace the OsTende theme with an actively maintained alternative; (2) if removal is not immediately possible, deploy a Web Application Firewall (WAF) rule to block LFI patterns; (3) restrict file system permissions to limit exposure; and (4) monitor server logs for path traversal indicators (Patchstack).
Wordfence included CVE-2026-27986 in its weekly WordPress vulnerability report for the period of March 2–8, 2026, highlighting it as part of broader WordPress ecosystem security coverage. Patchstack, which coordinated the disclosure, assigned it a "High" priority and noted the class of vulnerability is commonly leveraged in mass-exploit campaigns against WordPress sites. No significant independent researcher commentary or broader media coverage has been identified beyond these security vendor reports (Wordfence, Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."