CVE-2026-22380
8.1AncoraThemes · UnlimHost
AncoraThemes UnlimHost is vulnerable to local file inclusion due to improper control of filenames in PHP include or require statements, allowing unauthorized file access.
Executive summary
A high-severity local file inclusion vulnerability in the AncoraThemes UnlimHost WordPress theme exposes the host system to unauthorized file access and potential remote code execution.
Vulnerability
The theme fails to properly sanitize user-supplied input used in PHP include or require statements, which constitutes a local file inclusion vulnerability. This flaw can be triggered by an unauthenticated attacker via the network.
Business impact
This vulnerability carries a CVSS score of 8.1, reflecting its high potential for impact on confidentiality, integrity, and availability. Successful exploitation allows an attacker to read arbitrary files on the server, which may lead to the disclosure of sensitive configuration data or facilitate full system compromise through code execution.
Remediation
Immediate Action: Since a specific patch version is not currently identified, administrators should immediately disable or remove the UnlimHost theme if it is not business-critical. If the theme must remain active, contact the vendor for an urgent security update.
Proactive Monitoring: Review web server access logs for suspicious patterns, such as directory traversal characters or unexpected file path references in URL parameters.
Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to block common local file inclusion attack patterns and directory traversal attempts.
Exploitation status
Public Exploit Available: No — there is no confirmed public exploit or weaponized module available in our curated sources.
Analyst recommendation
Given the high severity of this vulnerability, immediate defensive action is required to protect the hosting environment. Organizations should prioritize removing or updating the vulnerable UnlimHost theme to prevent unauthorized access and potential escalation to remote code execution.
More AncoraThemes CVEs
Sources
Originally found and disclosed by Tran Nguyen Bao Khanh (VCI - VNPT Cyber Immunity) | Patchstack Bug Bounty Program, per the CVE Program record.