
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-28058 is a Local File Inclusion (LFI) vulnerability in the ThemeREX Dixon WordPress theme, classified under CWE-98 (Improper Control of Filename for Include/Require Statement in PHP Program). It affects Dixon versions up to and including 1.4.2.1 and allows unauthenticated remote attackers to include and execute arbitrary local files on the server. The vulnerability was published on March 5, 2026, with Patchstack credited as the assigner. It carries a CVSS v3.1 base score of 8.1 (High) (Feedly, Patchstack).
The root cause is improper control of filename parameters used in PHP include/require statements within the Dixon theme (CWE-98, mapped to CAPEC-193: PHP Remote File Inclusion). An attacker can manipulate file path parameters passed to these inclusion functions to reference arbitrary local files on the server, bypassing intended access controls. Exploitation requires no authentication and no user interaction, though the attack complexity is rated High, suggesting specific conditions or non-default configurations must be met. No public proof-of-concept code has been identified at this time (Feedly).
Successful exploitation allows an attacker to read sensitive local files (e.g., configuration files containing database credentials, WordPress wp-config.php) and potentially execute arbitrary PHP code if attacker-controlled content can be included. This can result in full confidentiality, integrity, and availability compromise of the affected WordPress installation, including unauthorized data access, content manipulation, and service disruption. Lateral movement within a shared hosting environment is also a risk if sensitive credentials are exposed (Feedly).
There is currently no public proof-of-concept exploit and no confirmed evidence of in-the-wild exploitation. The EPSS score is approximately 0.053%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The High attack complexity rating suggests that exploitation is not trivial and may require specific preconditions to be met (Feedly).
style.css files.include/require statements.../../../../wp-config.php) to reference sensitive local files.wp-config.php.../, ..%2F, ....//) in query parameters or POST body fields./uploads/) that may have been placed for inclusion; access timestamps on sensitive files like wp-config.php updated unexpectedly.www-data) executing shell commands or making outbound network connections.Users should update the ThemeREX Dixon theme to a version newer than 1.4.2.1 as soon as a patched release becomes available from the vendor. In the interim, the following mitigations are recommended: disable PHP's allow_url_include directive in php.ini; implement strict server-side input validation and sanitization for all file inclusion parameters; restrict file system access via web server configuration (e.g., open_basedir restrictions); and monitor web server logs for path traversal patterns. Consider temporarily deactivating the theme if no business-critical dependency exists (Feedly).
Wordfence included this vulnerability in their weekly WordPress vulnerability report covering February 23 – March 1, 2026, highlighting it as part of a broader set of theme-related issues. Patchstack, which discovered and reported the vulnerability, published it to their database and assigned the CVE. No significant broader media coverage or notable researcher commentary beyond these standard disclosure channels has been identified (Wordfence, Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."