<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Mane (1.7) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/mane-1.7/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 25 Aug 2026 08:06:31 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/mane-1.7/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Local File Inclusion Vulnerability in Mane WordPress Theme</title><link>https://feed.craftedsignal.io/briefs/2026-08-mane-wordpress-lfi/</link><pubDate>Tue, 25 Aug 2026 08:06:31 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-mane-wordpress-lfi/</guid><description>The Mane WordPress theme versions 1.7 and earlier contain a Local File Inclusion (LFI) vulnerability that allows unauthenticated attackers to execute arbitrary PHP code on the host server.</description><content:encoded><![CDATA[<p>The Mane theme for WordPress, developed by Elated-Themes, contains a critical Local File Inclusion (LFI) vulnerability identified as CVE-2026-78478. The flaw exists in all versions up to and including 1.7. This vulnerability allows an unauthenticated remote attacker to manipulate input parameters to include and execute arbitrary files present on the server. If an attacker can successfully upload a file to the server (e.g., via a profile picture upload or other media feature) or access existing configuration files, they can force the application to interpret that file as PHP code. Successful exploitation results in remote code execution (RCE) with the privileges of the web server process, potentially leading to total site compromise, data exfiltration, and administrative access bypass.</p>
<h2 id="impact">Impact</h2>
<p>The vulnerability carries a CVSS 3.1 base score of 8.1, reflecting its high impact on confidentiality, integrity, and availability. Successful exploitation enables unauthenticated attackers to execute arbitrary code, bypass security controls, and access sensitive application data. The scope of impact includes any WordPress installation running the affected Mane theme version, which is widely used for portfolio and creative websites.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Update the Mane WordPress theme to the latest version immediately to remediate the LFI vulnerability.</li>
<li>Review web server access logs for anomalous URI requests containing directory traversal sequences (e.g., ../) or unusual file extensions in parameters.</li>
<li>Audit the WordPress media library and upload directories for unauthorized or suspicious file uploads that could be leveraged as LFI targets.</li>
<li>Deploy the provided WAF/IDS rules to detect and block exploitation attempts targeting the identified vulnerable theme parameters.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category></item></channel></rss>