
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-28117 is a PHP Local File Inclusion (LFI) vulnerability in the Axiomthemes "smart SEO" WordPress theme, classified under CWE-98 (Improper Control of Filename for Include/Require Statement in PHP Program). It affects all versions of the smart SEO theme through version 2.9. The vulnerability was published on March 5, 2026, and was reported by Patchstack. It carries a CVSS v3.1 base score of 8.1 (High), assigned by CISA-ADP (Patchstack, Wordfence).
The root cause is improper sanitization of user-controlled input passed to PHP include or require statements within the smart SEO theme (CWE-98), enabling an attacker to manipulate the filename parameter to reference arbitrary local files on the server. The attack vector is network-based, requires no authentication or user interaction, but has high attack complexity (AC:H), suggesting that specific conditions or knowledge of the target environment may be needed to exploit it successfully. No public proof-of-concept code has been identified at this time (Patchstack).
Successful exploitation allows a remote, unauthenticated attacker to include and execute arbitrary PHP files present on the server's filesystem, resulting in high confidentiality, integrity, and availability impact. An attacker could read sensitive files (e.g., WordPress wp-config.php containing database credentials), modify website content, or achieve full system compromise. If combined with a file upload vulnerability, LFI can escalate to remote code execution (Patchstack).
There is no known public proof-of-concept exploit and no evidence of active in-the-wild exploitation as of the time of publication. The EPSS score is approximately 0.053%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported (Patchstack).
include() or require() call without proper sanitization.../../../../wp-config.php) to reference sensitive local files.wp-config.php), which can be leveraged for further compromise such as database access or lateral movement (Patchstack).../, ..%2F, %2e%2e%2f) in query parameters targeting the smart SEO theme endpoints.wp-config.php, /etc/passwd, or PHP session files.No official patch has been released by Axiomthemes for the smart SEO theme as of the vulnerability's publication date. Site administrators should immediately consider deactivating and removing the smart SEO theme until a patched version is available. As interim mitigations, deploying a Web Application Firewall (WAF) to block path traversal and file inclusion patterns, applying the principle of least privilege to the web server process, and monitoring application logs for suspicious include/require activity are recommended. Contact Axiomthemes directly for patch availability updates (Patchstack).
Wordfence included CVE-2026-28117 in its weekly WordPress vulnerability report covering the period of February 23 to March 1, 2026, highlighting it as part of a broader set of theme and plugin vulnerabilities (Wordfence). The vulnerability was also noted on social media via automated CVE notification accounts. No significant independent researcher commentary or major media coverage has been identified beyond standard vulnerability aggregator reporting.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."