
🔥 CyberForge CVE of the Day #034 🚨 CVE-2026-78478 — Elated-Themes Måne for WordPress ≤1.7 contains a High-severity unauthenticated Local File Inclusion flaw. Attackers may expose local data or execute PHP when a suitable attacker-influenced file already exists—no login or victim interaction required. 🔑 Key details: ⭐ Severity: High — CVSS 3.1: 8.1 🧠 Weakness: CWE-98 — PHP file inclusion 🎯 Target: Måne WordPress theme ≤1.7 🔓 Authentication: None 🌐 Attack vector: Network 👆 User interaction: None ⚙️ Complexity: High ⚔️ Impact: LFI, data exposure, conditional code execution 🛡️ Fix: No known patch; remove theme files or apply validated virtual patching 🚫 Exploitation/PoC: None publicly confirmed 📋 CISA KEV: Not listed — checked 26 August 2026 📈 EPSS: 0.487% — 39.715th percentile 🔎 Important record note: Patchstack calls this a duplicate of CVE-2026-66670. Both remain published, so track both. Version 1.8 exists but is not confirmed as the fix. ⚠️ Why it matters: Theme PHP is trusted server-side code. Inclusion could expose configuration secrets or execute PHP from an attacker-influenced local file. LFI is confirmed; instant one-request RCE is not. 🛡️ Affected Software & Versions: Elated-Themes Måne / Mane ≤1.7 Version 1.8 is outside the affected range but not a verified patch 🧠 The practical attack surface: The endpoint, PHP function and parameter are undisclosed. Inventory inactive copies too: deactivation may leave reachable theme files on disk. 🔥 CyberForge verdict: High priority for public sites carrying Måne ≤1.7. Remove it unless Elated-Themes confirms a repaired build. Exploitation signals are low, but unauthenticated LFI deserves swift action. 🔗 Full visual advisory: https://github.com/advisories/GHSA-h4m2-w2c9-4x9f 🔗 Full vulnerability details: https://nvd.nist.gov/vuln/detail/CVE-2026-78478 #CyberSecurity #CVE #WordPress #LFI #CyberForge
Post summary
CVE-2026-78478 is a high‑severity unauthenticated LFI in the Måne WordPress theme, lacking a known patch but necessitating removal or virtual patching; no active exploitation or PoC has been reported.
