Vulnerability Name: Prodigy Commerce <= 3.2.9 - Unauthenticated Local File Inclusion via parameters[template_name] CVE: CVE-2026-0926 CVSS Score: 9.8 (Critical) Publicly Published: February 18, 2026 Last Updated: February 19, 2026 Researchers: Athiwat Tirasaharn (Jitlada), Itthidej Aramsri (Boeing777), Waris Damkham CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Description: The Prodigy Commerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.2.9 via the 'parameters[template_name]' parameter. This can be exploited to include and read arbitrary files, or execute arbitrary PHP code. Software Type: Plugin Software Slug: prodigy-commerce Patched?: No Remediation: No known patch available. Consider uninstalling the affected software. Affected Version: <= 3.2.9