Critical severity9.8NVD Advisory· Published Mar 5, 2026· Updated Jun 17, 2026
CVE-2026-28043
CVE-2026-28043
Description
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Healer - Doctor, Clinic & Medical WordPress Theme healer allows PHP Local File Inclusion.This issue affects Healer - Doctor, Clinic & Medical WordPress Theme: from n/a through <= 1.0.0.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- Range: <=1.0.0
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.