
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-28052 is a PHP Local File Inclusion (LFI) vulnerability in the ThemeREX Peter Mason WordPress theme, classified under CWE-98 (Improper Control of Filename for Include/Require Statement in PHP Program). It affects all versions of the Peter Mason theme up to and including 1.4.5. The vulnerability was published on March 5, 2026, and was reported by Patchstack. It carries a CVSS v3.1 base score of 8.1 (High) (Feedly, Patchstack).
The root cause is improper control of filename parameters passed to PHP include or require statements within the Peter Mason WordPress theme (CWE-98). An unauthenticated remote attacker can manipulate filename inputs to cause the server to include arbitrary local files, enabling Local File Inclusion (LFI). Exploitation requires high attack complexity (e.g., specific preconditions such as knowledge of file paths or chaining with other vulnerabilities), but no authentication or user interaction is needed. No public proof-of-concept code has been identified at this time (Feedly, Patchstack).
Successful exploitation of this LFI vulnerability could allow an attacker to read sensitive server-side files, including WordPress configuration files (wp-config.php), database credentials, and other confidential data. Beyond information disclosure, attackers may leverage exposed credentials for lateral movement, database access, or further compromise of the hosting environment. In scenarios where file upload functionality exists or log poisoning is possible, LFI can be escalated to remote code execution, potentially resulting in full server compromise (Feedly).
As of the time of reporting, there is no known public proof-of-concept exploit and no evidence of active in-the-wild exploitation. The vulnerability has an EPSS score of approximately 0.053% (0.000530), indicating a low probability of exploitation in the near term. It has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. The vulnerability was disclosed by Patchstack and affects a WordPress theme with a limited install base (Feedly, Patchstack).
Update the ThemeREX Peter Mason WordPress theme to a version newer than 1.4.5 as soon as a patched release becomes available. As interim mitigations, disable allow_url_include in the PHP configuration if remote file inclusion is not required, and implement strict input validation on any filename parameters used in include/require statements. Monitor web server and PHP error logs for unusual file inclusion patterns or access attempts to sensitive files such as wp-config.php. Consider using a WordPress security plugin or WAF to detect and block LFI-style request patterns (Feedly, Patchstack).
The vulnerability was noted in the Wordfence Intelligence Weekly WordPress Vulnerability Report covering the period of February 23 to March 1, 2026, indicating routine tracking by the WordPress security community. No significant vendor statements, researcher commentary, or broader media coverage has been identified beyond standard vulnerability database listings (Wordfence).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."