Description
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in don-themes Wolmart wolmart allows PHP Local File Inclusion.This issue affects Wolmart: from n/a through <= 1.9.6.
Published: 2026-03-05
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Local File Inclusion enabling arbitrary file access and potential code execution
Action: Immediate Patch
AI Analysis

Impact

The Vulnerability arises from improper control of the filename used in PHP include/require statements within the Wolmart theme. An attacker can supply a crafted value that causes the application to read arbitrary files on the server, potentially including PHP scripts that could be executed when the file is included. This flaw allows disclosure of sensitive data such as configuration files and, if attacker‑controlled PHP files are included, code execution with the privileges of the web server. The weakness corresponds to CWE‑98, "Improper Control of Filename for Include/Require Statement".

Affected Systems

The issue affects the don‑themes Wolmart WordPress theme up to and including version 1.9.6. No specific sub‑versions are listed beyond the overall range, so all releases in that range are considered vulnerable.

Risk and Exploitability

The CVSS v3 score of 8.1 places the flaw in the high severity category, and the EPSS score of less than 1 % indicates a very low probability of widespread exploitation at this time. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that attackers would most likely target websites running the affected theme via unauthenticated HTTP requests that trigger the vulnerable inclusion logic. Successful exploitation would provide the attacker with arbitrary file access on the host, potentially leading to information disclosure or remote code execution if the attacker can place and include malicious PHP files.

Generated by OpenCVE AI on April 17, 2026 at 12:56 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Wolmart theme to the latest release available from don‑themes, ensuring any update that addresses the include logic is installed.
  • Configure the theme or WordPress environment to use a strict whitelist for file inclusion paths, rejecting any user‑supplied filenames that are not explicitly allowed.
  • Restrict file system permissions for the web‑root and configuration files so that the web server process cannot read sensitive files such as wp-config.php or other password‑protected files.

Generated by OpenCVE AI on April 17, 2026 at 12:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 10 Mar 2026 14:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 06 Mar 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Don-themes
Don-themes wolmart
Wordpress
Wordpress wordpress
Vendors & Products Don-themes
Don-themes wolmart
Wordpress
Wordpress wordpress

Thu, 05 Mar 2026 06:15:00 +0000

Type Values Removed Values Added
Description Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in don-themes Wolmart wolmart allows PHP Local File Inclusion.This issue affects Wolmart: from n/a through <= 1.9.6.
Title WordPress Wolmart theme <= 1.9.6 - Local File Inclusion vulnerability
Weaknesses CWE-98
References

Subscriptions

Don-themes Wolmart
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-01T14:13:41.268Z

Reserved: 2026-01-07T12:21:40.878Z

Link: CVE-2026-22385

cve-icon Vulnrichment

Updated: 2026-03-10T13:09:46.697Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-03-05T06:16:13.103

Modified: 2026-03-10T18:18:06.733

Link: CVE-2026-22385

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-17T13:00:12Z

Weaknesses