PHP Local File Inclusion Flaw in ThemeREX Equadio by WordPress
CVE-2026-27988

8.1HIGH

Key Information:

Vendor

WordPress

Status
Vendor
CVE Published:
5 March 2026

What is CVE-2026-27988?

The PHP Remote File Inclusion vulnerability in the ThemeREX Equadio theme allows for the improper control of filename parameters, leading to Local File Inclusion. Attackers may exploit this weakness to access sensitive files on the server, potentially exposing critical information or allowing further attacks. This flaw affects versions of Equadio from n/a through 1.1.3, highlighting the importance of timely updates and security practices for users of this WordPress theme.

Affected Version(s)

Equadio 0 <= 1.1.3

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Bonds | Patchstack Bug Bounty Program
.