
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-28019 is a PHP Local File Inclusion (LFI) vulnerability in the ThemeREX Manoir WordPress theme, classified under CWE-98 (Improper Control of Filename for Include/Require Statement in PHP Program). It affects all versions of the Manoir theme through version 1.11 and was published on March 2–5, 2026, with discovery credited to Tran Nguyen Bao Khanh of VCI - VNPT Cyber Immunity, who reported it on September 30, 2025. The vulnerability carries a CVSS v3.1 base score of 8.1 (High), exploitable remotely without authentication or user interaction, though with high attack complexity (Patchstack).
The root cause is improper control of filename parameters used in PHP include/require statements within the Manoir theme (CWE-98), allowing an attacker to manipulate file path inputs to include arbitrary local files on the server. The attack vector is network-based, requiring no privileges or user interaction, but is classified as high complexity, suggesting specific conditions or non-default configurations must be met for exploitation. An attacker can leverage this to read sensitive local files such as configuration files containing database credentials or other server-side secrets. The vulnerability is mapped to CAPEC-193 (PHP Remote File Inclusion) and was assigned by Patchstack (Patchstack).
Successful exploitation allows an unauthenticated remote attacker to include and execute arbitrary local files on the web server, resulting in high confidentiality, integrity, and availability impacts. Sensitive files such as WordPress configuration files (wp-config.php) containing database credentials could be exposed, potentially enabling complete database takeover. Depending on server configuration, this could also facilitate further lateral movement within the hosting environment (Patchstack).
As of the time of publication, there is no known public proof-of-concept exploit and no confirmed in-the-wild exploitation of CVE-2026-28019. The EPSS score is approximately 0.053%, indicating a low current probability of exploitation in the near term. No threat actor attribution has been made, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Patchstack notes that vulnerabilities of this class and severity are frequently used in mass-exploit campaigns targeting WordPress sites (Patchstack).
include() or require() without adequate sanitization.../../../../wp-config.php or /etc/passwd) using path traversal sequences.wp-config.php) to access the database directly or escalate privileges within the WordPress installation (Patchstack).../, ..%2F, %2e%2e%2f) in query parameters or POST body fields.wp-config.php, /etc/passwd, or other system files by the web server process.As of the disclosure date, no official patch has been released by ThemeREX for the Manoir theme. Users are advised to immediately upgrade to a version newer than 1.11 if one becomes available, or consider disabling or replacing the theme in the interim. Patchstack has issued a virtual patching/mitigation rule for its subscribers to block exploitation attempts until an official fix is available. Additional hardening measures include implementing strict input validation for file inclusion parameters, applying least-privilege file system permissions, and monitoring web application logs for path traversal attempts (Patchstack).
The vulnerability was included in Wordfence's weekly WordPress vulnerability report for the period of March 2–8, 2026, indicating it received standard industry tracking attention. No notable individual researcher commentary or significant social media discussion has been identified beyond routine CVE announcement channels. Patchstack, as the assigning authority, flagged it as high priority and noted its potential for use in mass-exploit campaigns targeting WordPress sites (Wordfence, Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."