Report: CVE-2026-27065 - WordPress BuilderPress plugin <= 2.0.1 - local file inclusion vulnerability

Report: CVE-2026-27065 - WordPress BuilderPress plugin <= 2.0.1 - local file inclusion vulnerability

CVE ID :CVE-2026-27065 Published : March 19, 2026, 9:16 a.m. | 19 minutes ago Description :Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThimPress BuilderPress allows PHP Local File Inclusion.This issue affects BuilderPress: from n/a through 2.0.1. Severity: 9.8 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE Details

Severity
CRITICAL
Published
March 19, 2026
Affected Product: PHP
Attack Vector: Local