What the vulnerability does
01Description
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in XpeedStudio Bajaar - Highly Customizable WooCommerce WordPress Theme bajaar allows PHP Local File Inclusion.This issue affects Bajaar - Highly Customizable WooCommerce WordPress Theme: from n/a through <= 2.1.0.
Explanation of Vulnerability in Simple Terms
02Summary
The Bajaar WooCommerce theme for WordPress contains a code injection vulnerability affecting versions up to 2.1.0. An attacker can inject and execute arbitrary code on the site without authentication. The vulnerability requires specific conditions to exploit but can lead to complete site compromise, including data theft and malware installation.
What an attacker can do
03Attacker Capabilities
Run arbitrary code on the site, steal data, modify content, or install malware.
Potential impact on your site
04Site Impact
Complete compromise of the WordPress site, including customer data, payment info, and admin access.
Conditions required to exploit
05Prerequisites
Network access to the site; specific attack conditions must be met (high complexity).
Key dates
06Disclosure timeline
January 22, 2026
CVE published
April 28, 2026
Record updated