CVE-2026-28061

8.1

ThemeREX · Tiger Claw

A Local File Inclusion vulnerability in the ThemeREX Tiger Claw theme allows unauthenticated attackers to include arbitrary files, potentially leading to full system compromise.

Executive summary

The ThemeREX Tiger Claw theme is vulnerable to Local File Inclusion, which permits unauthenticated attackers to access sensitive files or execute code on the host server.

Vulnerability

This flaw is a Local File Inclusion (CWE-98) occurring due to improper control of filenames used in include or require statements. The vulnerability is exploitable by an unauthenticated attacker over the network.

Business impact

This vulnerability carries a CVSS score of 8.1, indicating a high level of severity due to the potential for total impact on confidentiality, integrity, and availability. Successful exploitation could allow an attacker to read sensitive configuration files, steal database credentials, or achieve remote code execution, resulting in significant data breaches and prolonged service outages.

Remediation

Immediate Action: Since a specific patch version is currently unavailable, administrators should immediately deactivate or uninstall the Tiger Claw theme if it is not essential to business operations.

Proactive Monitoring: Monitor server access logs for anomalous requests containing directory traversal patterns, such as sequences of dots and slashes, directed at the theme directory.

Compensating Controls: Implement a Web Application Firewall (WAF) rule to block requests containing directory traversal characters or unexpected file inclusion attempts targeting the theme path.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Given the potential for complete system compromise, this vulnerability poses a severe risk to any WordPress environment utilizing the Tiger Claw theme. Organizations are urged to prioritize the removal or replacement of this theme immediately, as no official patch is currently confirmed. Maintain heightened vigilance until the vendor releases a secure update and it is verified in your environment.

More ThemeREX CVEs

Sources

Originally found and disclosed by Bonds | Patchstack Bug Bounty Program, per the CVE Program record.