CVE-2026-28062
Published: 05 March 2026
Summary
CVE-2026-28062 is a high-severity PHP Remote File Inclusion (CWE-98) vulnerability. Its CVSS base score is 8.1 (High).
Operationally, exploitation aligns with the MITRE ATT&CK technique Exploit Public-Facing Application (T1190); ranked at the 32.0th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.
The strongest mitigations our analysis identified are NIST 800-53 SI-10 (Information Input Validation) and SI-2 (Flaw Remediation).
Deeper analysis
CVE-2026-28062 is an Improper Control of Filename for Include/Require Statement in PHP Program vulnerability, classified as PHP Remote File Inclusion but enabling PHP Local File Inclusion, in the ThemeREX Happy Baby WordPress theme (happy-baby). This issue affects versions from n/a through 1.2.12, as published on 2026-03-05. It is associated with CWE-98 and carries a CVSS v3.1 base score of 8.1 (AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H), indicating high severity due to significant impacts on confidentiality, integrity, and availability.
The vulnerability can be exploited by unauthenticated attackers over the network (AV:N), requiring no privileges (PR:N) or user interaction (UI:N), though it demands high attack complexity (AC:H) with unchanged scope (S:U). Successful exploitation allows attackers to achieve high-level compromise of confidentiality, integrity, and availability, potentially enabling local file reads or further abuse depending on server configuration.
The Patchstack advisory at https://patchstack.com/database/Wordpress/Theme/happy-baby/vulnerability/wordpress-happy-baby-theme-1-2-12-local-file-inclusion-vulnerability?_s_id=cve details this Local File Inclusion vulnerability in Happy Baby theme version 1.2.12, serving as the primary reference for mitigation guidance.
OWASP Top 10 for Web (2025)
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2026-9722
Vulnerability details
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Happy Baby happy-baby allows PHP Local File Inclusion.This issue affects Happy Baby: from n/a through <= 1.2.12.
- CWE(s)
Related Threats
MITRE ATT&CK Enterprise TechniquesAI
Why these techniques?
CVE describes exploitation of a public-facing WordPress theme vulnerability (T1190) enabling local file inclusion for data extraction from the local system (T1005), potentially leading to code execution.
CVEs Like This One
Affected Assets
Mitigating Controls
Mitigating Controls (NIST 800-53 r5) AI
Directly remediates the specific LFI vulnerability in the Happy Baby WordPress theme by requiring timely identification, prioritization, and correction of the PHP include/require flaw.
Requires validation of inputs to PHP include/require statements to block path traversal and unauthorized local file inclusion attempts.
Enforces secure PHP configuration settings like open_basedir restrictions and disabling dangerous functions to limit the scope of LFI exploitation on the server filesystem.