Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
8.1

MoneyFlow ThemeREX MoneyFlow allows attackers to read local files

CVE-2026-28028
Summary

A security flaw in the MoneyFlow plugin for WordPress allows an attacker to read any file on the website's server. This makes it possible for hackers to gain sensitive information and potentially steal data or disrupt the site. Update the MoneyFlow plugin to the latest version to fix this issue.

Original title
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX MoneyFlow moneyflow allows PHP Local File Inclusion.This issue affe...
Original description
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX MoneyFlow moneyflow allows PHP Local File Inclusion.This issue affects MoneyFlow: from n/a through <= 1.0.
nvd CVSS3.1 8.1
Vulnerability type
CWE-98 Improper Control of Filename for Include
Published: 5 Mar 2026 · Updated: 13 Mar 2026 · First seen: 6 Mar 2026