VYPR

Mikado Core

by WordPress

CVEs (3)

  • CVE-2026-39538HigApr 8, 2026
    risk 0.49cvss 7.5epss 0.00

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Mikado Core mikado-core allows PHP Local File Inclusion.This issue affects Mikado Core: from n/a through <= 1.6.

  • CVE-2025-9058MedSep 9, 2025
    risk 0.42cvss 6.4epss 0.00

    The Mikado Core plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and including, 1.5.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers…

  • CVE-2026-39537Jun 17, 2026
    risk 0.00cvss epss 0.00

    Unauthenticated Local File Inclusion in Mikado Core <= 1.6 versions.