Executive brief
The Mane theme is a WordPress template used by website designers to create portfolio sites. An unauthenticated attacker can exploit a local file inclusion flaw to execute arbitrary PHP code on the server, potentially allowing complete control of the website, theft of sensitive data, or deployment of malware.
Technical details
The Mane WordPress theme contains a local file inclusion (LFI) vulnerability in all versions up to and including 1.7 that allows unauthenticated attackers to include and execute arbitrary files on the server. The vulnerability can be exploited by including PHP code hosted on uploaded files (such as images or other "safe" file types) and causing the server to execute that code. No authentication is required to exploit this flaw, and it is network-accessible. An attacker can achieve arbitrary PHP code execution, leading to unauthorized access, data theft, or full server compromise. A patch is required to address this vulnerability.
Affected products
- Mane Mane WordPress Theme up to and including 1.7
Timeline
- 2026-08-25: disclosed