Junglewise Threat Intelligence

CVE-2026-66670: Måne WordPress theme local file inclusion

CVE-2026-66670 · Severity: high · CVSS 8.1 · Published 2026-08-24

Executive brief

Måne is a WordPress theme used to display website content and design. An unauthenticated attacker can exploit this vulnerability to read sensitive files stored on the web server, potentially exposing configuration data, database credentials, or other confidential information that could lead to a full site compromise.

Technical details

The Måne WordPress theme versions 1.7 and earlier contain a Local File Inclusion (LFI) vulnerability that allows unauthenticated attackers to read arbitrary files from the server filesystem. The vulnerability is in the theme's file handling logic and can be exploited via a network request without requiring authentication or user interaction. An attacker can retrieve sensitive files such as wp-config.php (containing database credentials), configuration files, or other server files, potentially enabling complete site takeover. No official patch is currently available; mitigation via web application firewall rules is recommended.

Affected products

  • Måne Måne WordPress Theme 1.7 and earlier

Timeline

  • 2026-08-20: disclosed: Vulnerability published by Patchstack
  • 2026-08-24: advisory: CVE-2026-66670 assigned

References