Prodigy Commerce WordPress plugin <= 3.2.9 contains a local file inclusion caused by improper sanitization of 'parameters[template_name]' parameter, letting unauthenticated attackers include and execute arbitrary files remotely.
id: CVE-2026-0926
info:
name: Prodigy Commerce <= 3.3.0 - Local File Inclusion
author: Shivam K
...