WordPress security by component
mane
mane is a WordPress theme with 2 published CVE records in this archive. The latest tracked vulnerability was published Aug 25, 2026; the highest published CVSS base score is 8.1.
Theme slug:
maneLatest vulnerability
CVE-2026-78478: Mane permits unauthenticated local file inclusion
The Mane theme through 1.7 permits an unauthenticated attacker to include arbitrary local server files. This can disclose sensitive data and can execute PHP where an attacker can place an otherwise accepted file and then include it.
| Safe version |
|
||
|---|---|---|---|
| Aug 25, 2026 |
CVE-2026-78478
Mane permits unauthenticated local file inclusion
The Mane theme through 1.7 permits an unauthenticated attacker to include arbitrary local server files. This can disclose sensitive data and can execute PHP where an attacker can place an otherwise accepted file and then include it.
|
See mitigation notes |
CVE8.1
NVDPending
|
| Aug 24, 2026 |
CVE-2026-66670
Måne permits unauthenticated local file inclusion
Måne through 1.7 permits an unauthenticated attacker to influence a local file-inclusion operation under an undisclosed high-complexity condition. Successful exploitation can expose local files and may execute included PHP, compromising site confidentiality, integrity, and availability.
|
See mitigation notes |
CVE8.1
NVDPending
|