CVE-2026-27079
Received Received - Intake
Local File Inclusion Vulnerability in Mikado-Themes Amfissa

Publication date: 2026-03-25

Last updated on: 2026-04-23

Assigner: Patchstack

Description
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Amfissa amfissa allows PHP Local File Inclusion.This issue affects Amfissa: from n/a through <= 1.1.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-03-25
Last Modified
2026-04-23
Generated
2026-05-27
AI Q&A
2026-03-25
EPSS Evaluated
2026-05-25
NVD
EUVD
Affected Vendors & Products
Showing 2 associated CPEs
Vendor Product Version / Range
mikado-themes amfissa to 1.1 (inc)
mikado-themes amfissa From 1.0 (inc) to 1.1 (inc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-98 The PHP application receives input from an upstream component, but it does not restrict or incorrectly restricts the input before its usage in "require," "include," or similar functions.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

CVE-2026-27079 is a Local File Inclusion (LFI) vulnerability affecting the WordPress Amfissa Theme versions 1.1 and earlier.

This vulnerability allows unauthenticated attackers to include and read local files from the target website's server.

By exploiting this flaw, attackers can potentially access sensitive information such as database credentials.


How can this vulnerability impact me? :

Exploitation of this vulnerability can lead to severe security breaches including exposure of sensitive files and data.

Attackers may gain access to database credentials, which could result in a complete database takeover depending on the website's configuration.

Because the vulnerability requires no authentication, it can be exploited by anyone, increasing the risk of mass attacks.


What immediate steps should I take to mitigate this vulnerability?

Immediate mitigation is recommended using Patchstack’s protection rules to block attacks exploiting this vulnerability until an official patch is released and safely applied.

Users are advised to update the affected WordPress Amfissa Theme to a version later than 1.1 if possible.

If updating is not possible, seek assistance from your hosting provider or web developer to implement mitigations.


How does this vulnerability affect compliance with common standards and regulations (like GDPR, HIPAA)?:

The CVE-2026-27079 vulnerability allows unauthenticated attackers to include and read local files on the target website, potentially exposing sensitive information such as database credentials.

Exposure of sensitive data due to this vulnerability could lead to a complete database takeover, which may result in unauthorized access to personal or protected information.

Such unauthorized data exposure and compromise can negatively impact compliance with common standards and regulations like GDPR and HIPAA, which require protection of sensitive personal and health information.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart