
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-28020 is a Local File Inclusion (LFI) vulnerability in the ThemeREX Chroma WordPress theme affecting all versions through 1.11. Classified under CWE-98 (Improper Control of Filename for Include/Require Statement in PHP Program), it allows unauthenticated network attackers to include and execute arbitrary local files on the server. The vulnerability was reported on September 30, 2025, by Tran Nguyen Bao Khanh (VCI - VNPT Cyber Immunity) and publicly disclosed on March 2–5, 2026. It carries a CVSS v3.1 base score of 8.1 (High) (Patchstack, Feedly).
The root cause is improper control of filename parameters used in PHP include/require statements within the Chroma theme (CWE-98), which maps to CAPEC-193 (PHP Remote File Inclusion). Despite the CWE classification referencing remote file inclusion, the exploitable behavior is Local File Inclusion (LFI), where an attacker manipulates a filename parameter passed to a PHP include function to reference arbitrary files on the server's filesystem. Exploitation requires no authentication and no user interaction, though attack complexity is rated High, suggesting some precondition or bypass is needed (e.g., specific server configuration or path traversal). No public proof-of-concept code has been identified at this time (Patchstack, Feedly).
Successful exploitation allows an attacker to include and execute arbitrary local files on the web server, potentially exposing sensitive files such as WordPress configuration files (wp-config.php) containing database credentials, which could lead to full database compromise. The vulnerability carries HIGH impact on confidentiality, integrity, and availability, enabling unauthorized data access, remote code execution (if combined with file upload or log poisoning), and potential lateral movement within the hosting environment (Patchstack, Feedly).
There is no confirmed public proof-of-concept exploit or evidence of in-the-wild exploitation at this time. The EPSS score is approximately 0.053% (0.000530), indicating a low current probability of exploitation. No threat actor attribution has been made, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Patchstack notes that vulnerabilities of this class (LFI with CVSS 8.1) are frequently used in mass-exploit campaigns targeting WordPress sites regardless of traffic size (Patchstack, Feedly).
/wp-content/themes/chroma/style.css for version metadata) or tools like WPScan.include or require statement — typically via a GET/POST parameter controlling template or file selection.../../../../wp-config.php or /etc/passwd) in the vulnerable parameter to reference sensitive local files.wp-config.php), enabling further compromise such as database access or escalation to RCE via log poisoning (Patchstack).../, ..%2F, %2e%2e%2f) in query parameters; requests targeting sensitive file paths such as wp-config.php or /etc/passwd.wp-config.php, /etc/passwd, or server log files; presence of web shells in the theme directory if LFI is chained with file upload.As of the disclosure date, no official patch from ThemeREX is available for the Chroma theme. Immediate recommended actions include: disabling or removing the Chroma theme if not actively required; implementing Patchstack's virtual patching/mitigation rule, which has been issued to block exploitation attempts until an official patch is released; deploying Web Application Firewall (WAF) rules to block path traversal and file inclusion patterns; restricting filesystem permissions to limit exposure of sensitive files; and monitoring web server logs for suspicious file inclusion attempts. Site owners should check the Patchstack advisory and ThemeREX for patch availability (Patchstack).
The vulnerability was included in Wordfence's weekly WordPress vulnerability report for the period of March 2–8, 2026, indicating broad community awareness within the WordPress security ecosystem. Patchstack, which discovered and disclosed the vulnerability, has issued a virtual mitigation rule for its users. No significant vendor statement from ThemeREX or notable independent researcher commentary has been identified beyond the initial disclosure (Wordfence, Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."