🔐 CVE Alert

CVE-2026-32531

HIGH 8.1

WordPress Kunco theme < 1.4.5 - Local File Inclusion vulnerability

CVSS Score
8.1
EPSS Score
0.0%
EPSS Percentile
0th

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in gavias Kunco kunco allows PHP Local File Inclusion.This issue affects Kunco: from n/a through < 1.4.5.

CWE CWE-98
Vendor gavias
Product kunco
Published Mar 25, 2026
Last Updated Mar 25, 2026
Stay Ahead of the Next One

Get instant alerts for gavias kunco

Be the first to know when new high vulnerabilities affecting gavias kunco are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

gavias / Kunco
n/a ≤ < 1.4.5

References

NVD ↗ CVE.org ↗ EPSS Data ↗
patchstack.com: https://patchstack.com/database/Wordpress/Theme/kunco/vulnerability/wordpress-kunco-theme-1-4-5-local-file-inclusion-vulnerability?_s_id=cve

Credits

João Pedro S Alcântara (Kinorth) | Patchstack Bug Bounty Program