WordPress security by component
shuffle
shuffle is a WordPress theme with 3 published CVE records in this archive. The latest tracked vulnerability was published Aug 25, 2026; the highest published CVSS base score is 8.5.
Theme slug:
shuffleLatest vulnerability
CVE-2026-78566: Shuffle permits unauthenticated local file inclusion
The Shuffle theme through 1.8 permits an unauthenticated attacker to include arbitrary local server files. This can expose sensitive data and may execute PHP when an attacker can place an otherwise accepted file and then include it.
| Safe version |
|
||
|---|---|---|---|
| Aug 25, 2026 |
CVE-2026-78566
Shuffle permits unauthenticated local file inclusion
The Shuffle theme through 1.8 permits an unauthenticated attacker to include arbitrary local server files. This can expose sensitive data and may execute PHP when an attacker can place an otherwise accepted file and then include it.
|
See mitigation notes |
CVE8.1
NVDPending
|
| Aug 20, 2026 |
CVE-2025-15637
Shuffle permits unauthenticated local file inclusion
Shuffle <= 1.8 allows an unauthenticated attacker to influence a server-side file-inclusion operation. Local file disclosure or PHP execution may result depending on the selected file and server state; the CNA assigns high confidentiality, integrity and availability impact.
|
1.9 |
CVE8.1
NVDPending
|
| Mar 26, 2025 |
CVE-2025-28873
Shuffle: SQL injection
Shuffle is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE8.5
NVDPending
|