Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.

Ekoterra Theme Can Load Malicious Files from Anywhere

CVE-2026-27335
Summary

The Ekoterra theme for WordPress websites has a security weakness that allows an attacker to load and execute malicious files from any location. This means that if a malicious file is uploaded to the server, the theme may load and execute it, potentially allowing the attacker to steal sensitive information or take control of the website. To fix this issue, update the Ekoterra theme to a version 1.0.1 or later.

Original title
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Ekoterra - NonProfit, Green Energy & Ecology Theme ekoterra all...
Original description
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Ekoterra - NonProfit, Green Energy & Ecology Theme ekoterra allows PHP Local File Inclusion.This issue affects Ekoterra - NonProfit, Green Energy & Ecology Theme: from n/a through <= 1.0.0.
Vulnerability type
CWE-98 Improper Control of Filename for Include
Published: 5 Mar 2026 · Updated: 13 Mar 2026 · First seen: 6 Mar 2026