
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-28045 is a PHP Local File Inclusion (LFI) vulnerability in the ThemeREX N7 | Golf Club Sports & Events WordPress theme. It stems from improper control of filename parameters used in PHP include/require statements (CWE-98), allowing unauthenticated remote attackers to include arbitrary local files. All versions through 2.16.0 are affected. The vulnerability was published on March 5, 2026, with Patchstack credited as the assigner. It carries a CVSS v3.1 base score of 8.1 (High) (Feedly, Patchstack).
The root cause is classified under CWE-98 (Improper Control of Filename for Include/Require Statement in PHP Program), where user-supplied input is passed unsanitized to a PHP include() or require() call within the theme's codebase. An unauthenticated attacker can craft a network request that manipulates the filename parameter to point to arbitrary files on the server's local filesystem, causing PHP to include and execute their contents. Despite the CWE name referencing "Remote File Inclusion," the vulnerability's actual impact is Local File Inclusion (LFI), meaning the attacker is limited to files already present on the server. Exploitation requires high attack complexity (AC:H), suggesting that specific conditions or knowledge of the target environment must be met (Feedly, Patchstack).
Successful exploitation could allow an attacker to read sensitive local files (e.g., wp-config.php containing database credentials), execute arbitrary PHP code if writable files or log poisoning techniques are leveraged, and potentially achieve full compromise of the WordPress installation and its underlying server. The CVSS scoring reflects High impacts across confidentiality, integrity, and availability. This could facilitate credential theft, lateral movement within a hosting environment, or complete site takeover (Feedly).
As of the time of reporting, no public proof-of-concept exploit is known and no in-the-wild exploitation has been confirmed. The EPSS score is approximately 0.053%, indicating a low probability of exploitation in the near term. The vulnerability requires high attack complexity (AC:H), which raises the bar for successful exploitation. It has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported (Feedly, Patchstack).
/wp-content/themes/n7-golf-club/style.css).include() or require() call without proper sanitization.../../../../wp-config.php) or a path to a log file containing injected PHP code as the filename parameter.wp-config.php), or if log poisoning was used, execute arbitrary PHP commands to establish a web shell or exfiltrate data (Feedly).../, ..%2F, ....//) or references to sensitive files (wp-config, passwd, access.log)./wp-content/themes/n7-golf-club/); newly created or modified PHP files in writable directories.bash, curl, wget) following suspicious HTTP requests to the theme endpoint.The primary remediation is to update the N7 | Golf Club Sports & Events theme to a version newer than 2.16.0 as soon as a patched release is available from ThemeREX. If no patch is currently available, consider temporarily deactivating the theme and switching to an alternative to eliminate the attack surface. As a server-level hardening measure, ensure PHP's allow_url_include is disabled in php.ini and restrict file system access using open_basedir. Monitor web server access logs for path traversal patterns as a detective control (Feedly, Patchstack).
The vulnerability was included in Wordfence's weekly WordPress vulnerability report for the period of March 2–8, 2026, indicating routine tracking by the WordPress security community. No notable researcher commentary, vendor statements beyond the Patchstack advisory, or significant media coverage has been identified for this vulnerability (Wordfence).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."