CVE-2026-78478Disclosure

LOWCVSS 8.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The Mane theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.7. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-98

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-08-25); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-08-25: 1Mentions · 2026-08-26: 1Patch / Workaround · 2026-08-26: 1Technical Details · 2026-08-25: 1Technical Details · 2026-08-26: 108-2508-26
Signal classification1 categories
Disclosure
2100.0%
Referenced assets3 URLs
Full discourse2 posts
  • lee1981@lee1981b
    Disclosure

    🔥 CyberForge CVE of the Day #034 🚨 CVE-2026-78478 — Elated-Themes Måne for WordPress ≤1.7 contains a High-severity unauthenticated Local File Inclusion flaw. Attackers may expose local data or execute PHP when a suitable attacker-influenced file already exists—no login or victim interaction required. 🔑 Key details: ⭐ Severity: High — CVSS 3.1: 8.1 🧠 Weakness: CWE-98 — PHP file inclusion 🎯 Target: Måne WordPress theme ≤1.7 🔓 Authentication: None 🌐 Attack vector: Network 👆 User interaction: None ⚙️ Complexity: High ⚔️ Impact: LFI, data exposure, conditional code execution 🛡️ Fix: No known patch; remove theme files or apply validated virtual patching 🚫 Exploitation/PoC: None publicly confirmed 📋 CISA KEV: Not listed — checked 26 August 2026 📈 EPSS: 0.487% — 39.715th percentile 🔎 Important record note: Patchstack calls this a duplicate of CVE-2026-66670. Both remain published, so track both. Version 1.8 exists but is not confirmed as the fix. ⚠️ Why it matters: Theme PHP is trusted server-side code. Inclusion could expose configuration secrets or execute PHP from an attacker-influenced local file. LFI is confirmed; instant one-request RCE is not. 🛡️ Affected Software & Versions: Elated-Themes Måne / Mane ≤1.7 Version 1.8 is outside the affected range but not a verified patch 🧠 The practical attack surface: The endpoint, PHP function and parameter are undisclosed. Inventory inactive copies too: deactivation may leave reachable theme files on disk. 🔥 CyberForge verdict: High priority for public sites carrying Måne ≤1.7. Remove it unless Elated-Themes confirms a repaired build. Exploitation signals are low, but unauthenticated LFI deserves swift action. 🔗 Full visual advisory: https://github.com/advisories/GHSA-h4m2-w2c9-4x9f 🔗 Full vulnerability details: https://nvd.nist.gov/vuln/detail/CVE-2026-78478 #CyberSecurity #CVE #WordPress #LFI #CyberForge

    Post summary

    The advisory discloses a high‑severity unauthenticated LFI vulnerability in Elated‑Themes Måne WordPress theme (≤1.7), provides technical details, and offers mitigation steps, but reports no PoC or active exploitation.

    0001082
    564 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-78478 Local File Inclusion in WordPress Mane Theme Up To Version 1.7 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-78478

    Post summary

    CVE‑2026‑78478 is a Local File Inclusion vulnerability affecting WordPress Mane Theme up to version 1.7. The post only identifies the issue; no PoC, exploit, patch, or active exploitation details are provided.

    00000120
    4.1K followersView on X

Explore more