
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-28015 is a PHP Local File Inclusion (LFI) vulnerability in the ThemeREX ShiftCV WordPress theme, classified under CWE-98 (Improper Control of Filename for Include/Require Statement in PHP Program). It affects ShiftCV versions up to and including 3.0.14, with no official patch available as of the time of disclosure. The vulnerability was reported by researcher "Bonds" on October 4, 2025, and published by Patchstack on March 2, 2026. It carries a CVSS v3.1 base score of 8.1 (High) (Patchstack).
The root cause is improper validation and sanitization of filename parameters used in PHP include/require statements within the ShiftCV theme (CWE-98). An unauthenticated remote attacker can manipulate these parameters over the network to force the application to include arbitrary local PHP files, potentially exposing sensitive server-side content or executing malicious code. The attack requires high complexity (AC:H) but no privileges or user interaction, making it exploitable without authentication. Patchstack has issued a virtual patching/mitigation rule to block exploitation attempts until an official fix is released (Patchstack).
Successful exploitation allows an attacker to include and read arbitrary local files on the web server, potentially exposing sensitive credentials such as database configuration files (e.g., wp-config.php). Depending on server configuration, this could escalate to remote code execution if an attacker can control file contents (e.g., via log poisoning). The vulnerability carries HIGH impact across confidentiality, integrity, and availability, and could enable lateral movement within the server environment or full database compromise (Patchstack).
No public proof-of-concept exploit code has been identified, and there is no evidence of active in-the-wild exploitation at this time. The EPSS score is approximately 0.053%, indicating a low but non-negligible probability of exploitation in the near term. No threat actor attribution has been made, and the vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Patchstack classifies this as high priority, noting that vulnerabilities of this type are commonly used in mass-exploit campaigns targeting WordPress sites (Patchstack).
include/require statement without proper sanitization.../../../../wp-config.php or /etc/passwd) using path traversal sequences.wp-config.php.../, ..%2F, %2e%2e%2f) in query parameters or POST body fields.wp-config.php, /etc/passwd, or server log files by the web server process.No official patch from ThemeREX is available for ShiftCV as of the disclosure date. Organizations running ShiftCV ≤ 3.0.14 should consider temporarily disabling the theme until a patch is released. Patchstack has issued a virtual patching rule that blocks exploitation attempts for users of its service. Additional mitigations include deploying a Web Application Firewall (WAF) with rules to detect and block path traversal and LFI patterns, enforcing strict input validation on all filename parameters, and monitoring server logs for suspicious file access activity (Patchstack).
Wordfence included CVE-2026-28015 in its weekly WordPress vulnerability report for the period of March 2–8, 2026, highlighting it among notable disclosures for that week. Patchstack, the assigning organization, classified the vulnerability as high priority and noted its potential for use in mass-exploit campaigns. No significant broader media coverage or notable researcher commentary beyond these sources has been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."