CVE-2026-28013 | ThemeREX Kratz Plugin up to 1.0.12 on WordPress filename control
A vulnerability, which was classified as critical, was found in ThemeREX Kratz Plugin up to 1.0.12 on WordPress. The affected element is an unknown function. Executing a manipulation can lead to improper control of filename for include/require statement in php program ('php remote file inclusion').
This vulnerability is handled as CVE-2026-28013. The attack can be executed remotely. There is not any exploit available.