
CVE-2026-22449 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Select-Themes Don Peppe donpeppe allows PHP L… https://www.cve.org/CVERecord?id=CVE-2026-22449
Post summary
A new CVE, CVE-2026-22449, is disclosed describing a PHP Remote File Inclusion flaw in the Select‑Themes Don Peppe donpeppe plugin.
