Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Magentech SW Core allows PHP Local File Inclusion. This issue affects SW Core: from n/a through 1.7.18.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
This vulnerability represents a critical weakness in input validation and file handling within the Magentech SW Core plugin (versions through 1.7.18). PHP Local File Inclusion (LFI) vulnerabilities occur when an application improperly controls filenames used in include or require statements, allowing attackers to include and execute arbitrary local files on the server. This is particularly dangerous in WordPress environments where Magentech SW Core is deployed, as attackers can leverage this to read sensitive configuration files (wp-config.php), execute malicious code, or chain the vulnerability with other weaknesses to achieve remote code execution. Organizations running affected versions of this plugin face immediate risk of data exposure and system compromise, making this a high-priority patching requirement.
Casky.ai's platform identifies attack patterns associated with file inclusion vulnerabilities by mapping observed behaviors to reconnaissance and execution techniques across the MITRE ATT&CK framework. When analyzing this CVE, practitioners would see detection signals related to suspicious file path manipulation, unusual include/require statements with user-controlled input, and attempts to access sensitive files outside intended directories. The extended reasoning capabilities of Claude AI help security teams correlate indicators such as abnormal file system access patterns, parameter tampering in plugin requests, and path traversal sequences (../../, etc.) that precede successful exploitation. While this specific CVE lacks direct MITRE technique mappings, practitioners using Casky would benefit from its broader skill library to identify the pre-exploitation reconnaissance phase (T1592 - Gather Victim Host Information) and subsequent execution attempts that LFI vulnerabilities enable in their environment.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-39661. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation