** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.
No vendor fix or workaround currently provided.
OpenCVE Recommended Actions
- Upgrade the Shuffle theme to the latest available version that removes the LFI flaw (versions above 1.8).
- Identify and delete any uploaded files in the theme’s directories that could be included, especially those with PHP extensions or executable permissions.
- Configure the web server to deny PHP execution in upload and theme directories by setting appropriate permissions or using .htaccess directives to prevent local file inclusion.
Generated by OpenCVE AI on August 25, 2026 at 09:20 UTC.
Tracking
Sign in to view the affected projects.
No advisories yet.
No reference.
Tue, 01 Sep 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Shuffle <= 1.8 - Unauthenticated Local File Inclusion | |
| Weaknesses | CWE-98 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Tue, 01 Sep 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Shuffle theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.8. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included. | ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage. |
Tue, 25 Aug 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 25 Aug 2026 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Edge Themes
Edge Themes shuffle Wordpress Wordpress wordpress |
|
| Vendors & Products |
Edge Themes
Edge Themes shuffle Wordpress Wordpress wordpress |
Tue, 25 Aug 2026 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Shuffle theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.8. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included. | |
| Title | Shuffle <= 1.8 - Unauthenticated Local File Inclusion | |
| Weaknesses | CWE-98 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: REJECTED
Assigner: Wordfence
Published:
Updated: 2026-09-01T13:21:26.656Z
Reserved: 2026-08-24T20:18:41.733Z
Link: CVE-2026-78566
Updated:
Status : Rejected
Published: 2026-08-25T09:17:36.427
Modified: 2026-09-01T14:17:41.520
Link: CVE-2026-78566
No data.
OpenCVE Enrichment
Updated: 2026-08-25T09:30:05Z
No weakness.