Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
AncoraThemes Chronicle Theme Allows Attackers to Access Local Files
CVE-2026-27337
Summary
The AncoraThemes Chronicle WordPress theme has a security flaw that allows attackers to access and potentially steal sensitive files on a website. This means that an attacker could potentially access and view sensitive information on your website. To fix this issue, update the AncoraThemes Chronicle theme to the latest version.
Original title
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Chronicle - Lifestyle Magazine & Blog WordPress Theme chronicle...
Original description
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Chronicle - Lifestyle Magazine & Blog WordPress Theme chronicle allows PHP Local File Inclusion.This issue affects Chronicle - Lifestyle Magazine & Blog WordPress Theme: from n/a through <= 1.0.
Vulnerability type
CWE-98
Improper Control of Filename for Include
Published: 5 Mar 2026 · Updated: 13 Mar 2026 · First seen: 6 Mar 2026