CVE-2026-28056 | ThemeREX MCKinneys Politics Plugin up to 1.2.8 on WordPress filename control
A vulnerability identified as critical has been detected in ThemeREX MCKinneys Politics Plugin up to 1.2.8 on WordPress. This affects an unknown function. Performing a manipulation results in improper control of filename for include/require statement in php program ('php remote file inclusion').
This vulnerability is identified as CVE-2026-28056. The attack can be initiated remotely. There is not any exploit available.