CVE-2026-66670Disclosure

LOWCVSS 8.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Unauthenticated Local File Inclusion in Måne <= 1.7 versions.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-98

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-08-26: 1Patch / Workaround · 2026-08-26: 1Technical Details · 2026-08-26: 108-26
Signal classification1 categories
Disclosure
1100.0%
Referenced assets2 URLs
Full discourse1 post
  • lee1981@lee1981b
    Disclosure

    🔥 CyberForge CVE of the Day #034 🚨 CVE-2026-78478 — Elated-Themes Måne for WordPress ≤1.7 contains a High-severity unauthenticated Local File Inclusion flaw. Attackers may expose local data or execute PHP when a suitable attacker-influenced file already exists—no login or victim interaction required. 🔑 Key details: ⭐ Severity: High — CVSS 3.1: 8.1 🧠 Weakness: CWE-98 — PHP file inclusion 🎯 Target: Måne WordPress theme ≤1.7 🔓 Authentication: None 🌐 Attack vector: Network 👆 User interaction: None ⚙️ Complexity: High ⚔️ Impact: LFI, data exposure, conditional code execution 🛡️ Fix: No known patch; remove theme files or apply validated virtual patching 🚫 Exploitation/PoC: None publicly confirmed 📋 CISA KEV: Not listed — checked 26 August 2026 📈 EPSS: 0.487% — 39.715th percentile 🔎 Important record note: Patchstack calls this a duplicate of CVE-2026-66670. Both remain published, so track both. Version 1.8 exists but is not confirmed as the fix. ⚠️ Why it matters: Theme PHP is trusted server-side code. Inclusion could expose configuration secrets or execute PHP from an attacker-influenced local file. LFI is confirmed; instant one-request RCE is not. 🛡️ Affected Software & Versions: Elated-Themes Måne / Mane ≤1.7 Version 1.8 is outside the affected range but not a verified patch 🧠 The practical attack surface: The endpoint, PHP function and parameter are undisclosed. Inventory inactive copies too: deactivation may leave reachable theme files on disk. 🔥 CyberForge verdict: High priority for public sites carrying Måne ≤1.7. Remove it unless Elated-Themes confirms a repaired build. Exploitation signals are low, but unauthenticated LFI deserves swift action. 🔗 Full visual advisory: https://github.com/advisories/GHSA-h4m2-w2c9-4x9f 🔗 Full vulnerability details: https://nvd.nist.gov/vuln/detail/CVE-2026-78478 #CyberSecurity #CVE #WordPress #LFI #CyberForge

    Post summary

    CVE-2026-78478 is a high‑severity unauthenticated LFI in the Måne WordPress theme, lacking a known patch but necessitating removal or virtual patching; no active exploitation or PoC has been reported.

    0001082
    564 followersView on X

Explore more