What the vulnerability does
01Description
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes MoveMe moveme allows PHP Local File Inclusion.This issue affects MoveMe: from n/a through <= 1.2.15.
Explanation of Vulnerability in Simple Terms
02Summary
MoveMe versions 1.2.15 and earlier contain a remote code execution vulnerability. An attacker can exploit this flaw over the network without authentication to run arbitrary code on the affected site. The vulnerability requires specific conditions to be met (high attack complexity), but successful exploitation grants full control over the site's functionality, data, and availability.
What an attacker can do
03Attacker Capabilities
Run their own code on the site to steal data, modify content, or take the site offline.
Potential impact on your site
04Site Impact
Complete compromise of the site: attackers can access all data, modify any content, or disable the site entirely.
Conditions required to exploit
05Prerequisites
Network access to the site; no authentication required, but specific conditions must be met to exploit.
Key dates
06Disclosure timeline
January 22, 2026
CVE published
April 28, 2026
Record updated