CVE-2026-28128 - WordPress Verse theme <= 1.7.0 - local file inclusion vulnerability

CVE-2026-28128 - WordPress Verse theme <= 1.7.0 - local file inclusion vulnerability

CVE ID : CVE-2026-28128 Published : March 5, 2026, 6:16 a.m. | 1 hour, 10 minutes ago Description : Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Verse verse allows PHP Local File Inclusion.This issue affects Verse: from n/a through <=Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE Details

Published
March 5, 2026
Affected Product: PHP
Attack Vector: Local