CVE-2026-22385 | don-themes Wolmart Plugin up to 1.9.6 on WordPress filename control
A vulnerability was found in don-themes Wolmart Plugin up to 1.9.6 on WordPress. It has been declared as critical. Impacted is an unknown function. Such manipulation leads to improper control of filename for include/require statement in php program ('php remote file inclusion').
This vulnerability is traded as CVE-2026-22385. The attack may be launched remotely. There is no exploit available.