CVE-2026-28013
Published: 05 March 2026
Summary
CVE-2026-28013 is a high-severity PHP Remote File Inclusion (CWE-98) vulnerability. Its CVSS base score is 8.1 (High).
Operationally, exploitation aligns with the MITRE ATT&CK technique Exploit Public-Facing Application (T1190); ranked at the 32.0th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.
The strongest mitigations our analysis identified are NIST 800-53 CM-6 (Configuration Settings) and SI-10 (Information Input Validation).
Deeper analysis
CVE-2026-28013 is an Improper Control of Filename for Include/Require Statement in PHP Program vulnerability, known as PHP Remote File Inclusion, that enables PHP Local File Inclusion in the ThemeREX Kratz WordPress theme. This issue affects Kratz versions from n/a through 1.0.12 and is associated with CWE-98. The vulnerability was published on 2026-03-05 with a CVSS v3.1 base score of 8.1 (AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
Unauthenticated remote attackers can exploit this vulnerability over the network, though it requires high attack complexity and no user interaction. Successful exploitation allows high-impact compromise of confidentiality, integrity, and availability, potentially enabling local file inclusion to read sensitive files or, in some cases, lead to further code execution depending on the included files.
The Patchstack advisory provides details on this Local File Inclusion vulnerability in the Kratz WordPress theme version 1.0.12, including mitigation guidance, available at https://patchstack.com/database/Wordpress/Theme/kratz/vulnerability/wordpress-kratz-theme-1-0-12-local-file-inclusion-vulnerability?_s_id=cve.
OWASP Top 10 for Web (2025)
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2026-9675
Vulnerability details
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Kratz kratz allows PHP Local File Inclusion.This issue affects Kratz: from n/a through <= 1.0.12.
- CWE(s)
Related Threats
MITRE ATT&CK Enterprise TechniquesAI
Why these techniques?
Vulnerability in public-facing WordPress theme enables remote exploitation via local file inclusion (T1190), directly facilitating access to and potential execution of local system files (T1005).
CVEs Like This One
Affected Assets
Mitigating Controls
Mitigating Controls (NIST 800-53 r5) AI
Directly mitigates improper filename control in PHP include/require by requiring validation of user-supplied inputs to prevent local file inclusion of arbitrary files.
Requires timely discovery, assessment, and patching of the specific LFI flaw in Kratz WordPress theme versions through 1.0.12.
Enforces secure PHP configuration settings such as open_basedir restrictions to limit filesystem access and block LFI exploitation.