{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/edge-themes/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.1,"id":"CVE-2026-78566"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Shuffle"],"_cs_severities":["high"],"_cs_tags":["web-vulnerability","wordpress","cve-2026-78566"],"_cs_type":"advisory","_cs_vendors":["Edge-Themes"],"content_html":"\u003cp\u003eThe Shuffle theme for WordPress, developed by Edge-Themes, is susceptible to a Local File Inclusion (LFI) vulnerability identified as CVE-2026-78566. The vulnerability affects all versions up to and including 1.8. An unauthenticated attacker can exploit this flaw to include and execute arbitrary files stored on the underlying web server. This vulnerability, categorized as CWE-98, poses a significant risk to affected installations, as successful exploitation enables the execution of arbitrary PHP code, potentially leading to a full system compromise. The impact includes the ability to bypass access controls, exfiltrate sensitive application data, or achieve Remote Code Execution (RCE) if the environment allows for the uploading of files (such as images) that can then be processed via the LFI vector.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to execute arbitrary PHP code on the server hosting the WordPress instance. This can lead to unauthorized access to the WordPress database, configuration files, and credentials stored in the application environment. If the server is not properly hardened, this vulnerability may lead to full web shell deployment and persistent access by an adversary.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eIdentify all WordPress installations within the environment utilizing the Shuffle theme by Edge-Themes.\u003c/li\u003e\n\u003cli\u003eUpdate the Shuffle theme to the latest patched version immediately.\u003c/li\u003e\n\u003cli\u003eIf an update is unavailable, audit web server logs for suspicious requests containing directory traversal sequences (e.g., ../) in common URL parameters associated with theme file inclusion.\u003c/li\u003e\n\u003cli\u003eRestrict the ability of the web server user to read files outside of the defined document root.\u003c/li\u003e\n\u003cli\u003eDeploy the provided Sigma rule to detect attempts to exploit LFI vulnerabilities in web applications.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-25T10:08:09Z","date_published":"2026-08-25T10:08:09Z","id":"https://feed.craftedsignal.io/briefs/2026-08-shuffle-lfi/","summary":"The Shuffle WordPress theme (\u003c= 1.8) contains a Local File Inclusion vulnerability (CVE-2026-78566) that allows unauthenticated remote attackers to execute arbitrary PHP code on the host server.","title":"Local File Inclusion Vulnerability in Shuffle WordPress Theme","url":"https://feed.craftedsignal.io/briefs/2026-08-shuffle-lfi/"}],"language":"en","title":"CraftedSignal Threat Feed - Edge-Themes","version":"https://jsonfeed.org/version/1.1"}