CVE-2026-28088: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-28088 is a Local File Inclusion (LFI) vulnerability in the ThemeREX Aqualots WordPress theme, classified under CWE-98 (Improper Control of Filename for Include/Require Statement in PHP Program). It affects all versions of the Aqualots theme up to and including 1.1.6, allowing unauthenticated remote attackers to include and execute arbitrary local PHP files. The vulnerability was reported by security researcher "Bonds" on August 31, 2025, and published by Patchstack on February 27, 2026, with CVE assignment on March 5, 2026. It carries a CVSS v3.1 base score of 8.1 (High) (Patchstack).

Technical details

The root cause is improper sanitization and validation of user-controlled input passed to PHP include or require statements within the Aqualots theme (CWE-98). An attacker can manipulate a parameter that controls which file is included, causing the server to load and execute arbitrary local PHP files. The attack vector is network-based, requires no authentication or user interaction, but has high attack complexity, suggesting some precondition such as knowledge of a specific file path or parameter name. No public proof-of-concept exploit code has been identified at this time (Patchstack).

Impact

Successful exploitation can allow an unauthenticated attacker to read sensitive local files — such as WordPress configuration files (wp-config.php) containing database credentials — potentially leading to full database compromise. Beyond data theft, if an attacker can control file content (e.g., via log poisoning or uploaded files), LFI can escalate to remote code execution, resulting in complete web application compromise with high confidentiality, integrity, and availability impacts (Patchstack).

Exploitability

As of the time of publication, there is no known public proof-of-concept exploit and no evidence of active in-the-wild exploitation. The EPSS score is approximately 0.053%, indicating a low current probability of exploitation. No threat actor attribution has been made, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Patchstack has noted that vulnerabilities of this class are commonly used in mass-exploit campaigns targeting WordPress sites (Patchstack).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites using the Aqualots theme (version ≤ 1.1.6) via web crawlers, Shodan, or WordPress-specific scanners (e.g., WPScan).
  2. Parameter identification: Analyze the theme's PHP source code or HTTP responses to identify parameters passed to include/require statements that accept user-controlled input.
  3. Craft malicious request: Send an HTTP request (GET or POST) to the vulnerable endpoint with a manipulated file path parameter pointing to a sensitive local file (e.g., ../../../../wp-config.php or /etc/passwd).
  4. Extract sensitive data: Review the server's response for the contents of the included file, which may expose database credentials, API keys, or other sensitive configuration data.
  5. Escalate (optional): If file upload functionality exists on the site, upload a PHP web shell, then use the LFI to include and execute it, achieving remote code execution (Patchstack).

Indicators of compromise

  • Network: Unusual HTTP requests containing path traversal sequences (e.g., ../, ..%2F, %2e%2e%2f) in query parameters or POST body targeting the Aqualots theme endpoints.
  • Logs: Web server access logs showing requests with encoded or raw directory traversal patterns; repeated 200 responses to requests with file path parameters pointing to system files like wp-config.php or /etc/passwd.
  • File System: Unexpected PHP files or web shells uploaded to the WordPress uploads directory or theme directory; modification timestamps on theme files inconsistent with legitimate updates.
  • Process: Unusual child processes spawned by the web server process (e.g., bash, curl, wget) if LFI has been escalated to RCE via log poisoning or file upload.

Mitigation and workarounds

No official patch from ThemeREX is currently available for the Aqualots theme. As an immediate measure, Patchstack has issued a virtual patching/mitigation rule for its subscribers to block exploitation attempts. Site owners should consider deactivating the Aqualots theme until an official patch is released, or deploying a Web Application Firewall (WAF) with rules to block path traversal and file inclusion attempts. Additionally, implement strict input validation on any user-controlled parameters used in file include/require statements, and regularly review web server access logs for signs of exploitation (Patchstack).

Community reactions

Wordfence included this vulnerability in its weekly WordPress vulnerability report covering February 23 – March 1, 2026, highlighting it as part of broader WordPress ecosystem security monitoring. Patchstack, the assigning CNA, classified it as high priority and noted its potential for use in mass-exploit campaigns. No significant independent researcher commentary or broader media coverage has been identified beyond these standard vulnerability disclosure channels.

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management