PHP Remote File Inclusion Vulnerability in QantumThemes Kentha Elementor Widgets
CVE-2026-24390
Currently unrated
What is CVE-2026-24390?
A vulnerability has been identified in QantumThemes Kentha Elementor Widgets, allowing for local file inclusion due to improper control of filenames passed to include or require statements in PHP. This issue impacts versions up to 3.1, and can potentially enable attackers to execute arbitrary PHP code by including local files, which could compromise the entire site. Website owners using affected versions are advised to upgrade their plugins to mitigate this security risk.
Affected Version(s)
Kentha Elementor Widgets <= n/a
References
Timeline
Vulnerability published
Vulnerability Reserved
Credit
João Pedro S Alcântara (Kinorth) | Patchstack Bug Bounty Program