CVE-2026-28056 is a PHP Local File Inclusion vulnerability affecting ThemeREX MCKinney's Politics plugin versions up to and including 1.2.8. This flaw, rated 8.1 HIGH on CVSS, allows an unauthenticated attacker to include arbitrary local files due to improper control of filename in include/require statements. While the attack complexity is high, successful exploitation could lead to full compromise of confidentiality, integrity, and availability. There is currently no public exploit code available, and the vulnerability has not garnered significant community discussion or media coverage, indicating it is not actively exploited.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| ThemeREX | MCKinney'S Politics | >= 0, <= 1.2.8CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.