CVE-2026-22367 | AncoraThemes Coworking Plugin up to 1.6.1 on WordPress filename control
A vulnerability identified as critical has been detected in AncoraThemes Coworking Plugin up to 1.6.1 on WordPress. Affected by this issue is some unknown functionality. Performing a manipulation results in improper control of filename for include/require statement in php program ('php remote file inclusion').
This vulnerability is cataloged as CVE-2026-22367. It is possible to initiate the attack remotely. There is no exploit available.