SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-57789

HIGH · CVSS 7.5 EPSS 0.37%

Source: NVD + CISA KEV + EPSS · Published 2026-07-13 · Last synced 2026-08-12

CyberRota Analysis

AI-Generated

The vulnerability in the Aqua theme for PHP allows for local file inclusion due to improper control of filenames in include/require statements, potentially enabling attackers to execute arbitrary code on the server. This high-severity flaw affects versions up to 5.1.2 and poses a significant risk to any installations of the Aqua theme. Website administrators using this theme should prioritize patching or upgrading to mitigate the risk of exploitation.

CVE
CVE-2026-57789
Severity
HIGH
CVSS
7.5
EPSS
0.37%

Original NVD Description

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in jwsthemes Aqua aqua allows PHP Local File Inclusion.This issue affects Aqua: from n/a through <= 5.1.2.