CVE-2026-78566

8.1

Edge-Themes · Shuffle

The Edge-Themes Shuffle WordPress theme is vulnerable to Local File Inclusion, allowing unauthenticated attackers to potentially access or execute arbitrary files on the server.

Executive summary

A critical Local File Inclusion vulnerability in the Edge-Themes Shuffle WordPress theme poses a significant risk of unauthorized file access and remote code execution.

Vulnerability

This vulnerability involves the improper control of filenames for include statements, which allows an unauthenticated attacker to manipulate file paths. This flaw could lead to the inclusion of malicious files or the exposure of sensitive server configuration data.

Business impact

The exploitation of this vulnerability could lead to a complete compromise of the WordPress installation, including unauthorized access to sensitive data and potential remote code execution. Given the high CVSS score of 8.1, this issue represents a major security risk that could result in significant downtime, data breaches, and reputational harm to the organization.

Remediation

Immediate Action: Organizations using the Shuffle theme must confirm if they are running version 1.8 or lower and immediately update to a secure version if available or remove the theme.

Proactive Monitoring: Security teams should audit web server logs for suspicious requests containing directory traversal sequences, such as "../", which are commonly used in LFI attacks.

Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to block common directory traversal patterns and unauthorized file inclusion attempts.

Exploitation status

Public Exploit Available: No confirmed public exploit exists in our curated sources.

Analyst recommendation

The severity of this vulnerability necessitates immediate attention. Administrators should prioritize identifying and patching all instances of the Shuffle theme to prevent unauthorized access. If an update is not immediately available, disabling the theme is the most effective temporary mitigation.

More Edge-Themes CVEs