← WordPress Vulnerabilities
WordPress security by component

shuffle

shuffle is a WordPress theme with 3 published CVE records in this archive. The latest tracked vulnerability was published Aug 25, 2026; the highest published CVSS base score is 8.5.

Theme slug: shuffle

CVE-2026-78566: Shuffle permits unauthenticated local file inclusion

The Shuffle theme through 1.8 permits an unauthenticated attacker to include arbitrary local server files. This can expose sensitive data and may execute PHP when an attacker can place an otherwise accepted file and then include it.

PublishedAug 25, 2026
Safe version guidanceSee mitigation notes
Published vulnerabilities for shuffle
Safe version
Aug 25, 2026 CVE-2026-78566
Shuffle permits unauthenticated local file inclusion
The Shuffle theme through 1.8 permits an unauthenticated attacker to include arbitrary local server files. This can expose sensitive data and may execute PHP when an attacker can place an otherwise accepted file and then include it.
See mitigation notes
CVE8.1
NVDPending
Aug 20, 2026 CVE-2025-15637
Shuffle permits unauthenticated local file inclusion
Shuffle <= 1.8 allows an unauthenticated attacker to influence a server-side file-inclusion operation. Local file disclosure or PHP execution may result depending on the selected file and server state; the CNA assigns high confidentiality, integrity and availability impact.
1.9
CVE8.1
NVDPending
Mar 26, 2025 CVE-2025-28873
Shuffle: SQL injection
Shuffle is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE8.5
NVDPending