CVE-2026-39537 | Mikado-mes Mikado Core Plugin up to 1.6 on WordPress filename control

SecurityVulns

A vulnerability labeled as problematic has been found in Mikado-mes Mikado Core Plugin up to 1.6 on WordPress. Impacted is an unknown function. Such manipulation leads to improper control of filename for include/require statement in php program (‘php remote file inclusion’).

This vulnerability is listed as CVE-2026-39537. The attack may be performed from remote. There is no available exploit.VulDB Recent EntriesRead More