Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Scientia scientia al...
Description
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Scientia scientia allows PHP Local File Inclusion
Remediation
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
---METADATA---
VENDOR: Nexcess
PRODUCT: Kadence WooCommerce Email Designer
AFFECTED_VERSIONS: n/a through 1.5.19
CONFIDENCE: high
MISSING: none
---END_METADATA---
Description Summary:
The Kadence WooCommerce Email Designer plugin for WordPress contains a missing authorization vulnerability that allows unauthenticated attackers to escalate privileges.
Executive Summary:
This critical privilege escalation vulnerability in the Kadence WooCommerce Email Designer plugin allows unauthenticated attackers to achieve full administrative control over the affected WordPress installation.
Vulnerability Details
CVE-ID: CVE-2026-28005
Affected Software: Nexcess Kadence WooCommerce Email Designer
Affected Versions: n/a through 1.5.19
Vulnerability: The plugin fails to perform necessary capability checks, resulting in a CWE-862 Missing Authorization flaw. This allows an unauthenticated attacker to execute unauthorized actions, effectively bypassing security controls.
Business Impact
A successful exploit grants an attacker administrative privileges, leading to complete site compromise, data theft, and potential malware distribution. Given the CVSS score of 9.8, this vulnerability represents an existential threat to the integrity and availability of the affected web application.
Remediation Plan
Immediate Action: Update the Nexcess Kadence WooCommerce Email Designer plugin to version 1.5.19.1 or later immediately.
Proactive Monitoring: Review administrative user accounts for unauthorized creations or modifications and monitor server logs for suspicious POST requests targeting plugin endpoints.
Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to block unauthorized administrative requests and suspicious traffic patterns directed at the WordPress plugin directory.
Exploitation Status
Public Exploit Available: Unknown
Analyst Notes: As of August 6, 2026, there is no public information indicating active exploitation or a public proof-of-concept for this vulnerability. The flaw is highly dangerous due to the lack of required authentication, making it trivial to exploit if reachable by external traffic.
Analyst Recommendation
This vulnerability carries a critical severity rating and requires immediate attention from security teams. Organizations using this plugin must prioritize applying the vendor-provided patch to prevent unauthorized access and potential full system takeover.