CVE-2026-28098 | ThemeREX Save Life Plugin up to 1.2.13 on WordPress filename control
A vulnerability marked as critical has been reported in ThemeREX Save Life Plugin up to 1.2.13 on WordPress. Affected by this vulnerability is an unknown functionality. This manipulation causes improper control of filename for include/require statement in php program ('php remote file inclusion').
The identification of this vulnerability is CVE-2026-28098. It is possible to initiate the attack remotely. There is no exploit available.