SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-57800

HIGH · CVSS 7.5 EPSS 0.37%

Source: NVD + CISA KEV + EPSS · Published 2026-07-13 · Last synced 2026-08-12

CyberRota Analysis

AI-Generated

The vulnerability in Edge-Themes Overworld allows for local file inclusion due to improper control of filenames in PHP include/require statements, potentially enabling attackers to execute arbitrary PHP code on the server. This poses a significant risk to any installations of Overworld version 1.5 or earlier, as it could lead to unauthorized access or data manipulation. Organizations using this software should prioritize patching or mitigating this vulnerability to safeguard their systems against exploitation.

CVE
CVE-2026-57800
Severity
HIGH
CVSS
7.5
EPSS
0.37%

Original NVD Description

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Edge-Themes Overworld overworld allows PHP Local File Inclusion.This issue affects Overworld: from n/a through <= 1.5.