The Verdure Core plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.2. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
The Verdure Core plugin for WordPress contains a Local File Inclusion (LFI) vulnerability that allows unauthenticated attackers to include and execute arbitrary files on vulnerable servers. This vulnerability is particularly dangerous because it requires no authentication, meaning any internet-facing WordPress site running the affected plugin versions (up to 1.2) is immediately at risk. Attackers can leverage this flaw to execute arbitrary PHP code, potentially bypassing access controls, exfiltrating sensitive data including database credentials and configuration files, or establishing persistent backdoor access. Organizations using this plugin face significant exposure, especially if they also permit file uploads—a common feature that compounds the risk by providing attackers with a mechanism to stage malicious files for inclusion.
While this CVE lacks direct MITRE ATT&CK technique mapping, Casky's security skills powered by Claude would detect the underlying attack patterns associated with this vulnerability across multiple threat vectors. Practitioners would identify indicators consistent with Execution (T1059 - Command Line Interface, T1190 - Exploit Public-Facing Application), Defense Evasion (T1070 - Indicator Removal), and Credential Access (T1040 - Network Sniffing) techniques. A Casky analysis would flag suspicious patterns such as requests with file path traversal sequences (../, ..\, encoded variants), unexpected PHP file inclusions in parameter values, POST requests to plugin-specific endpoints with file parameters, and log entries showing execution of files from upload directories. Security teams would see correlated findings linking uploaded files to subsequent code execution, HTTP requests with LFI payloads, and anomalous process spawning—enabling rapid detection and response before exploitation.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-78562. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation