CVE-2026-22389 | Mikado-Themes Cocco Plugin up to 1.5.1 on WordPress filename control
A vulnerability categorized as critical has been discovered in Mikado-Themes Cocco Plugin up to 1.5.1 on WordPress. The impacted element is an unknown function. Executing a manipulation can lead to improper control of filename for include/require statement in php program ('php remote file inclusion').
This vulnerability is handled as CVE-2026-22389. The attack can be executed remotely. There is not any exploit available.