The Mane theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.7. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
The Mane theme for WordPress contains a Local File Inclusion (LFI) vulnerability affecting all versions through 1.7, allowing unauthenticated attackers to include and execute arbitrary files from the server. This is a critical vulnerability because it requires no authentication and can be exploited to execute arbitrary PHP code, effectively granting attackers the ability to compromise any WordPress site using this theme. The vulnerability becomes especially dangerous when combined with file upload functionality, as attackers can upload seemingly benign files (images, documents) and then use the LFI to include and execute them as PHP. Any organization using WordPress with the Mane theme is affected, regardless of their security posture or plugin ecosystem.
While this CVE currently lacks mapped MITRE ATT&CK techniques and Casky skills, practitioners should monitor for attack patterns associated with file inclusion exploitation. Detection would focus on identifying suspicious file inclusion attempts in web server logs—unusual parameters in URLs (such as "file=", "include=", or "page=" parameters with path traversal sequences like "../"), access attempts to sensitive system files (etc/passwd, wp-config.php), and POST requests to theme files with embedded PHP code. Security teams should use Casky's Claude-powered analysis to correlate these suspicious access patterns with file upload activities, identifying the temporal relationship between file uploads and subsequent inclusion attempts. This behavioral correlation helps distinguish legitimate theme functionality from exploitation attempts, enabling rapid identification of compromise and containment of malicious activity.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-78478. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation