Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
8.1

Green Thumb ThemeREX: Malicious files can be accessed through input

CVE-2026-28017
Summary

A security flaw in Green Thumb ThemeREX allows attackers to access sensitive files on your server. This means that if a hacker can trick your website into using their own file, they may be able to access and potentially steal sensitive information. To protect your site, update to a patched version of Green Thumb ThemeREX, or remove the plugin if an update is not available.

Original title
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Green Thumb greenthumb allows PHP Local File Inclusion.This issue a...
Original description
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Green Thumb greenthumb allows PHP Local File Inclusion.This issue affects Green Thumb: from n/a through <= 1.1.12.
nvd CVSS3.1 8.1
Vulnerability type
CWE-98 Improper Control of Filename for Include
Published: 5 Mar 2026 · Updated: 13 Mar 2026 · First seen: 6 Mar 2026