CVE-2026-66670

8.1

Elated-Themes · Måne

The Elated-Themes Måne WordPress theme contains an unauthenticated local file inclusion vulnerability that permits unauthorized file access.

Executive summary

An unauthenticated local file inclusion flaw in the Elated-Themes Måne WordPress theme creates a significant security risk for the underlying web server.

Vulnerability

The theme suffers from improper control of filenames in PHP include statements, which allows an unauthenticated attacker to include and potentially execute arbitrary local files on the server.

Business impact

With a CVSS score of 8.1, this vulnerability represents a severe threat to the security of the host system. If exploited, an attacker could read sensitive system files, configuration data, or achieve remote code execution, leading to total system compromise and potential data breach.

Remediation

Immediate Action: Check the vendor website for the latest version and apply the patch as soon as it becomes available. If no patch exists, consider deactivating the theme until a fix is released.

Proactive Monitoring: Review web server and application logs for unusual file inclusion patterns or unauthorized access attempts.

Compensating Controls: Utilize a Web Application Firewall (WAF) to filter out requests that attempt to traverse directories or include unauthorized local files.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

This is a critical vulnerability that requires immediate attention. Because the flaw allows for unauthenticated file inclusion, administrators should treat this as a high priority and monitor the vendor for a security update to remediate the underlying code flaw.

More Elated-Themes CVEs