CVE-2026-28128 | ThemeREX Verse Plugin up to 1.7.0 on WordPress filename control (EUVD-2026-9780)
A vulnerability labeled as critical has been found in ThemeREX Verse Plugin up to 1.7.0 on WordPress. This affects an unknown part. Such manipulation leads to improper control of filename for include/require statement in php program ('php remote file inclusion').
This vulnerability is uniquely identified as CVE-2026-28128. The attack can be launched remotely. No exploit exists.