PHP Remote File Inclusion Vulnerability in QantumThemes Kentha Elementor Widgets
CVE-2026-24390

Currently unrated

Key Information:

Vendor

WordPress

Vendor
CVE Published:
22 January 2026

What is CVE-2026-24390?

A vulnerability has been identified in QantumThemes Kentha Elementor Widgets, allowing for local file inclusion due to improper control of filenames passed to include or require statements in PHP. This issue impacts versions up to 3.1, and can potentially enable attackers to execute arbitrary PHP code by including local files, which could compromise the entire site. Website owners using affected versions are advised to upgrade their plugins to mitigate this security risk.

Affected Version(s)

Kentha Elementor Widgets <= n/a

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

João Pedro S Alcântara (Kinorth) | Patchstack Bug Bounty Program
.