CVE-2026-57788 | Edge-mes Aalto Plugin up to 1.8 on WordPress Include/Require Statement filename file inclusion
A vulnerability described as critical has been identified in Edge-mes Aalto Plugin up to 1.8 on WordPress. Affected is an unknown function of the component Include/Require Statement. The manipulation of the argument filename results in file inclusion.
This vulnerability is known as CVE-2026-57788. It is possible to launch the attack remotely. No exploit is available.