{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/mane-1.7/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.1,"id":"CVE-2026-78478"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Mane (1.7)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Elated-Themes"],"content_html":"\u003cp\u003eThe Mane theme for WordPress, developed by Elated-Themes, contains a critical Local File Inclusion (LFI) vulnerability identified as CVE-2026-78478. The flaw exists in all versions up to and including 1.7. This vulnerability allows an unauthenticated remote attacker to manipulate input parameters to include and execute arbitrary files present on the server. If an attacker can successfully upload a file to the server (e.g., via a profile picture upload or other media feature) or access existing configuration files, they can force the application to interpret that file as PHP code. Successful exploitation results in remote code execution (RCE) with the privileges of the web server process, potentially leading to total site compromise, data exfiltration, and administrative access bypass.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability carries a CVSS 3.1 base score of 8.1, reflecting its high impact on confidentiality, integrity, and availability. Successful exploitation enables unauthenticated attackers to execute arbitrary code, bypass security controls, and access sensitive application data. The scope of impact includes any WordPress installation running the affected Mane theme version, which is widely used for portfolio and creative websites.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the Mane WordPress theme to the latest version immediately to remediate the LFI vulnerability.\u003c/li\u003e\n\u003cli\u003eReview web server access logs for anomalous URI requests containing directory traversal sequences (e.g., ../) or unusual file extensions in parameters.\u003c/li\u003e\n\u003cli\u003eAudit the WordPress media library and upload directories for unauthorized or suspicious file uploads that could be leveraged as LFI targets.\u003c/li\u003e\n\u003cli\u003eDeploy the provided WAF/IDS rules to detect and block exploitation attempts targeting the identified vulnerable theme parameters.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-25T08:06:31Z","date_published":"2026-08-25T08:06:31Z","id":"https://feed.craftedsignal.io/briefs/2026-08-mane-wordpress-lfi/","summary":"The Mane WordPress theme versions 1.7 and earlier contain a Local File Inclusion (LFI) vulnerability that allows unauthenticated attackers to execute arbitrary PHP code on the host server.","title":"Local File Inclusion Vulnerability in Mane WordPress Theme","url":"https://feed.craftedsignal.io/briefs/2026-08-mane-wordpress-lfi/"}],"language":"en","title":"CraftedSignal Threat Feed - Mane (1.7)","version":"https://jsonfeed.org/version/1.1"}