CVE-2026-28052
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-28052 is a PHP Local File Inclusion (LFI) vulnerability in the ThemeREX Peter Mason WordPress theme, classified under CWE-98 (Improper Control of Filename for Include/Require Statement in PHP Program). It affects all versions of the Peter Mason theme up to and including 1.4.5. The vulnerability was published on March 5, 2026, and was reported by Patchstack. It carries a CVSS v3.1 base score of 8.1 (High) (Feedly, Patchstack).

Technical details

The root cause is improper control of filename parameters passed to PHP include or require statements within the Peter Mason WordPress theme (CWE-98). An unauthenticated remote attacker can manipulate filename inputs to cause the server to include arbitrary local files, enabling Local File Inclusion (LFI). Exploitation requires high attack complexity (e.g., specific preconditions such as knowledge of file paths or chaining with other vulnerabilities), but no authentication or user interaction is needed. No public proof-of-concept code has been identified at this time (Feedly, Patchstack).

Impact

Successful exploitation of this LFI vulnerability could allow an attacker to read sensitive server-side files, including WordPress configuration files (wp-config.php), database credentials, and other confidential data. Beyond information disclosure, attackers may leverage exposed credentials for lateral movement, database access, or further compromise of the hosting environment. In scenarios where file upload functionality exists or log poisoning is possible, LFI can be escalated to remote code execution, potentially resulting in full server compromise (Feedly).

Exploitability

As of the time of reporting, there is no known public proof-of-concept exploit and no evidence of active in-the-wild exploitation. The vulnerability has an EPSS score of approximately 0.053% (0.000530), indicating a low probability of exploitation in the near term. It has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. The vulnerability was disclosed by Patchstack and affects a WordPress theme with a limited install base (Feedly, Patchstack).

Mitigation and workarounds

Update the ThemeREX Peter Mason WordPress theme to a version newer than 1.4.5 as soon as a patched release becomes available. As interim mitigations, disable allow_url_include in the PHP configuration if remote file inclusion is not required, and implement strict input validation on any filename parameters used in include/require statements. Monitor web server and PHP error logs for unusual file inclusion patterns or access attempts to sensitive files such as wp-config.php. Consider using a WordPress security plugin or WAF to detect and block LFI-style request patterns (Feedly, Patchstack).

Community reactions

The vulnerability was noted in the Wordfence Intelligence Weekly WordPress Vulnerability Report covering the period of February 23 to March 1, 2026, indicating routine tracking by the WordPress security community. No significant vendor statements, researcher commentary, or broader media coverage has been identified beyond standard vulnerability database listings (Wordfence).

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-82923CRITICAL9.8
  • gw-website-builder-main
NoNoSep 04, 2026
CVE-2026-12483HIGH7.5
  • sfwd-lms
NoYesSep 04, 2026
CVE-2026-84045MEDIUM5.3
  • ecab-taxi-booking-manager
NoYesSep 04, 2026
CVE-2026-84044MEDIUM5.3
  • mp-restaurant-menu
NoYesSep 04, 2026
CVE-2026-84043MEDIUM5.3
  • epayco-gateway
NoYesSep 04, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management