CVE-2026-28118 | axiomthemes Welldone Plugin up to 2.4 on WordPress filename control (EUVD-2026-9770)
A vulnerability described as critical has been identified in axiomthemes Welldone Plugin up to 2.4 on WordPress. This issue affects some unknown processing. Executing a manipulation can lead to improper control of filename for include/require statement in php program ('php remote file inclusion').
The identification of this vulnerability is CVE-2026-28118. The attack may be launched remotely. There is no exploit available.