Local File Inclusion Vulnerability in Mane Theme for WordPress
CVE-2026-78478
8.1HIGH
What is CVE-2026-78478?
The Mane theme for WordPress presents a vulnerability that allows Local File Inclusion (LFI) in all versions up to and including 1.7. This vulnerability permits unauthenticated attackers to exploit the system by including and executing arbitrary files located on the server. Through this exploit, attackers can bypass access controls, potentially access sensitive data, and execute malicious PHP code embedded in files. This risk is particularly concerning as it may facilitate the inclusion of files disguised as 'safe' types, such as images. Users of the Mane theme are urged to take immediate action to secure their installations.
Affected Version(s)
Mane 0 <= 1.7