CVE-2026-78478CWE-98

CVE-2026-78478

High · published August 25, 2026

CVSS v3.1
8.1
EPSS
0%
Percentile
40.2
In the wild
Unconfirmed
What it is

The Mane theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.7. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.

The record
Technical detail
CVSS v3.1
8.1 · HIGH
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v4.0
Not supplied
EPSS
0.00487 · 40.2th percentile
Weakness
CWE-98 · Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
Published
2026-08-25T10:19Z
References (2)
EPSS history
Timeline
  • 26 AUG 08:27Z
    EPSS moved — → 0%
    epss
  • 25 AUG 05:31Z
    Måne <= 1.7 - Unauthenticated Local File Inclusion
    cvelistv5