
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-28088 is a Local File Inclusion (LFI) vulnerability in the ThemeREX Aqualots WordPress theme, classified under CWE-98 (Improper Control of Filename for Include/Require Statement in PHP Program). It affects all versions of the Aqualots theme up to and including 1.1.6, allowing unauthenticated remote attackers to include and execute arbitrary local PHP files. The vulnerability was reported by security researcher "Bonds" on August 31, 2025, and published by Patchstack on February 27, 2026, with CVE assignment on March 5, 2026. It carries a CVSS v3.1 base score of 8.1 (High) (Patchstack).
The root cause is improper sanitization and validation of user-controlled input passed to PHP include or require statements within the Aqualots theme (CWE-98). An attacker can manipulate a parameter that controls which file is included, causing the server to load and execute arbitrary local PHP files. The attack vector is network-based, requires no authentication or user interaction, but has high attack complexity, suggesting some precondition such as knowledge of a specific file path or parameter name. No public proof-of-concept exploit code has been identified at this time (Patchstack).
Successful exploitation can allow an unauthenticated attacker to read sensitive local files — such as WordPress configuration files (wp-config.php) containing database credentials — potentially leading to full database compromise. Beyond data theft, if an attacker can control file content (e.g., via log poisoning or uploaded files), LFI can escalate to remote code execution, resulting in complete web application compromise with high confidentiality, integrity, and availability impacts (Patchstack).
As of the time of publication, there is no known public proof-of-concept exploit and no evidence of active in-the-wild exploitation. The EPSS score is approximately 0.053%, indicating a low current probability of exploitation. No threat actor attribution has been made, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Patchstack has noted that vulnerabilities of this class are commonly used in mass-exploit campaigns targeting WordPress sites (Patchstack).
include/require statements that accept user-controlled input.../../../../wp-config.php or /etc/passwd).../, ..%2F, %2e%2e%2f) in query parameters or POST body targeting the Aqualots theme endpoints.wp-config.php or /etc/passwd.bash, curl, wget) if LFI has been escalated to RCE via log poisoning or file upload.No official patch from ThemeREX is currently available for the Aqualots theme. As an immediate measure, Patchstack has issued a virtual patching/mitigation rule for its subscribers to block exploitation attempts. Site owners should consider deactivating the Aqualots theme until an official patch is released, or deploying a Web Application Firewall (WAF) with rules to block path traversal and file inclusion attempts. Additionally, implement strict input validation on any user-controlled parameters used in file include/require statements, and regularly review web server access logs for signs of exploitation (Patchstack).
Wordfence included this vulnerability in its weekly WordPress vulnerability report covering February 23 – March 1, 2026, highlighting it as part of broader WordPress ecosystem security monitoring. Patchstack, the assigning CNA, classified it as high priority and noted its potential for use in mass-exploit campaigns. No significant independent researcher commentary or broader media coverage has been identified beyond these standard vulnerability disclosure channels.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."