CVE-2026-22324Disclosure

LOWCVSS 8.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Melania allows PHP Local File Inclusion.This issue affects Melania: from n/a through 2.5.0.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-98

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-03-20); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-20: 2Mentions · 2026-03-22: 1Technical Details · 2026-03-20: 2Technical Details · 2026-03-22: 103-2003-22
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-202
Disclosure2
2026-03-221
Disclosure1
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-22324 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Melania allows PHP Local File Inclus… https://www.cve.org/CVERecord?id=CVE-2026-22324

    Post summary

    The CVE-2026-22324 is a disclosure of a PHP include/require vulnerability in ThemeREX Melania that allows local file inclusion; no PoC, exploit code, active exploitation, or patch information is referenced.

    0000099
    56.8K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-22324 - High Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Melania allows PHP Local File Inclusion.This issue affects Me... https://www.thehackerwire.com/vulnerability/CVE-2026-22324/ https://t.co/01a2rK7szm

    Post summary

    The text announces CVE‑2026‑22324, highlights its high severity, explains it causes improper filename control leading to PHP local file inclusion, but does not provide PoC, exploit, active exploitation info, or remediation guidance.

    0000036
    138 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-22324 PHP Local File Inclusion Vulnerability in ThemeREX Melania WordPress Theme https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-22324

    Post summary

    The CVE is identified as a PHP Local File Inclusion vulnerability in the ThemeREX Melania WordPress theme, with no details on PoC, exploit code, active exploitation, or patch information in the provided text.

    0000030
    4.0K followersView on X

Explore more