Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes CasaMia | Property Rental Real Estate WordPress Theme casamia allows PHP Local File Inclusion.This issue affects CasaMia | Property Rental Real Estate WordPress Theme: from n/a through <= 1.1.2.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small standalone Python proof-of-concept exploit for CVE-2026-27097 affecting the AncoraThemes CasaMia WordPress theme, with a minimal README and one main script, CVE-2026-27097.py. The script is not part of a larger exploit framework. It uses requests for HTTP interaction, argparse for CLI control, and colorama for terminal output. The exploit’s purpose is to test and exploit a Local File Inclusion condition in CasaMia. The code defines a CasamiaLFIExploit class that initializes an HTTP session, optional proxy support, browser-like headers, and a list of likely vulnerable GET parameters such as page, file, include, template, view, load, module, path, theme_file, and custom_page. The vulnerability check routine builds requests against likely WordPress/theme paths and injects traversal payloads intended to read sensitive local files. It then inspects HTTP 200 responses for indicators like root:x:, boot loader, [fonts], mysql, and database to infer successful inclusion. Based on the visible code and CLI options, the script supports multiple modes: vulnerability checking only, reading an arbitrary file (default wp-config.php), extracting WordPress credentials from wp-config.php, attempting RCE through log poisoning, and generating a mitigation report. This makes it more than a simple detector; it is an operational PoC with basic post-read and post-exploitation logic. The RCE path is referenced in the interface and summary text, though the provided content is truncated, so exact implementation details are only partially visible. Fingerprintable targets and artifacts in the code include WordPress/theme HTTP paths (/wp-content/themes/casamia/some-page.php, /index.php, /?page_id=1), local file targets (/etc/passwd, C:\windows\win.ini, wp-config.php), and an example debugging proxy at http://127.0.0.1:8080. Overall, the repository is structured as a single-purpose exploit tool for remote LFI against a WordPress theme, with optional credential extraction and a likely log-poisoning-based RCE attempt.
1 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.