HIGH
UnTheme
CVE published 2026-04-08
CVE-2026-39684
The CVE-2026-39684 vulnerability is an Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') issue in the UnTheme OrganicFood theme, allowing PHP Local File Inclusion. This issue affects OrganicFood from n/a through version 3.6.4. The vulnerability has a CVSS score of 7.5 and a severity of HIGH. Users of the UnTheme OrganicFood theme, particularly those us [truncated]