Unauthenticated Local File Inclusion in Theme Test Drive by WordPress
CVE-2026-32464

8.1HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
18 August 2026

What is CVE-2026-32464?

The Theme Test Drive plugin for WordPress, prior to version 2.9.1, contains a security vulnerability that allows unauthenticated users to perform Local File Inclusion (LFI). This flaw could allow malicious actors to access sensitive files on the server, potentially leading to increased risk of further attacks. Users of affected versions should take immediate action to update their plugins to mitigate the risks associated with this vulnerability.

Affected Version(s)

Theme Test Drive <= 2.9.1

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Steven Julian | Patchstack Bug Bounty Program
.