CVE-2026-28069 | ThemeREX Le Truffe Plugin up to 1.1.7 on WordPress filename control

SecurityVulns

A vulnerability labeled as critical has been found in ThemeREX Le Truffe Plugin up to 1.1.7 on WordPress. Affected by this issue is some unknown functionality. The manipulation results in improper control of filename for include/require statement in php program (‘php remote file inclusion’).

This vulnerability is identified as CVE-2026-28069. The attack can be executed remotely. There is not any exploit available.VulDB Recent EntriesRead More