Report: CVE-2026-22324 - WordPress Melania theme <= 2.5.0 - local file inclusion vulnerability

Report: CVE-2026-22324 - WordPress Melania theme <= 2.5.0 - local file inclusion vulnerability

CVE ID :CVE-2026-22324 Published : March 20, 2026, 9:36 a.m. | 29 minutes ago Description :Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Melania allows PHP Local File Inclusion.This issue affects Melania: from n/a through 2.5.0. Severity: 8.1 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE Details

Severity
HIGH
Published
March 20, 2026
Affected Product: PHP
Attack Vector: Local