CVE-2026-28015: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-28015 is a PHP Local File Inclusion (LFI) vulnerability in the ThemeREX ShiftCV WordPress theme, classified under CWE-98 (Improper Control of Filename for Include/Require Statement in PHP Program). It affects ShiftCV versions up to and including 3.0.14, with no official patch available as of the time of disclosure. The vulnerability was reported by researcher "Bonds" on October 4, 2025, and published by Patchstack on March 2, 2026. It carries a CVSS v3.1 base score of 8.1 (High) (Patchstack).

Technical details

The root cause is improper validation and sanitization of filename parameters used in PHP include/require statements within the ShiftCV theme (CWE-98). An unauthenticated remote attacker can manipulate these parameters over the network to force the application to include arbitrary local PHP files, potentially exposing sensitive server-side content or executing malicious code. The attack requires high complexity (AC:H) but no privileges or user interaction, making it exploitable without authentication. Patchstack has issued a virtual patching/mitigation rule to block exploitation attempts until an official fix is released (Patchstack).

Impact

Successful exploitation allows an attacker to include and read arbitrary local files on the web server, potentially exposing sensitive credentials such as database configuration files (e.g., wp-config.php). Depending on server configuration, this could escalate to remote code execution if an attacker can control file contents (e.g., via log poisoning). The vulnerability carries HIGH impact across confidentiality, integrity, and availability, and could enable lateral movement within the server environment or full database compromise (Patchstack).

Exploitability

No public proof-of-concept exploit code has been identified, and there is no evidence of active in-the-wild exploitation at this time. The EPSS score is approximately 0.053%, indicating a low but non-negligible probability of exploitation in the near term. No threat actor attribution has been made, and the vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Patchstack classifies this as high priority, noting that vulnerabilities of this type are commonly used in mass-exploit campaigns targeting WordPress sites (Patchstack).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites using the ShiftCV theme (version ≤ 3.0.14) via web crawlers, Shodan, or WPScan fingerprinting.
  2. Identify vulnerable parameter: Locate the theme's PHP file inclusion point — a parameter passed to an include/require statement without proper sanitization.
  3. Craft malicious request: Send an unauthenticated HTTP request with a manipulated filename parameter pointing to a sensitive local file (e.g., ../../../../wp-config.php or /etc/passwd) using path traversal sequences.
  4. Extract sensitive data: Review the server response for included file contents, such as database credentials from wp-config.php.
  5. Escalate (optional): If server conditions allow (e.g., writable log files), attempt log poisoning by injecting PHP code into a log file and then including it via the LFI vector to achieve remote code execution (Patchstack).

Indicators of compromise

  • Network: Unusual HTTP GET/POST requests to ShiftCV theme endpoints containing path traversal sequences (e.g., ../, ..%2F, %2e%2e%2f) in query parameters or POST body fields.
  • Logs: WordPress or web server access logs showing requests with encoded traversal patterns targeting theme files; repeated 200 responses to requests with suspicious filename parameters.
  • File System: Unexpected access to sensitive files such as wp-config.php, /etc/passwd, or server log files by the web server process.
  • Process: PHP processes reading files outside the WordPress web root, or unexpected outbound connections from the web server process following file inclusion attempts.

Mitigation and workarounds

No official patch from ThemeREX is available for ShiftCV as of the disclosure date. Organizations running ShiftCV ≤ 3.0.14 should consider temporarily disabling the theme until a patch is released. Patchstack has issued a virtual patching rule that blocks exploitation attempts for users of its service. Additional mitigations include deploying a Web Application Firewall (WAF) with rules to detect and block path traversal and LFI patterns, enforcing strict input validation on all filename parameters, and monitoring server logs for suspicious file access activity (Patchstack).

Community reactions

Wordfence included CVE-2026-28015 in its weekly WordPress vulnerability report for the period of March 2–8, 2026, highlighting it among notable disclosures for that week. Patchstack, the assigning organization, classified the vulnerability as high priority and noted its potential for use in mass-exploit campaigns. No significant broader media coverage or notable researcher commentary beyond these sources has been identified.

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management