Executive brief
Måne is a WordPress theme used to display website content and design. An unauthenticated attacker can exploit this vulnerability to read sensitive files stored on the web server, potentially exposing configuration data, database credentials, or other confidential information that could lead to a full site compromise.
Technical details
The Måne WordPress theme versions 1.7 and earlier contain a Local File Inclusion (LFI) vulnerability that allows unauthenticated attackers to read arbitrary files from the server filesystem. The vulnerability is in the theme's file handling logic and can be exploited via a network request without requiring authentication or user interaction. An attacker can retrieve sensitive files such as wp-config.php (containing database credentials), configuration files, or other server files, potentially enabling complete site takeover. No official patch is currently available; mitigation via web application firewall rules is recommended.
Affected products
- Måne Måne WordPress Theme 1.7 and earlier
Timeline
- 2026-08-20: disclosed: Vulnerability published by Patchstack
- 2026-08-24: advisory: CVE-2026-66670 assigned