Solid Security Basic notify me that the Nirvana theme (<=version 2.6) is vulnerable to a high priority for “Local File Inclusion” risk.
https://patchstack.com/database/wordpress/theme/nirvana/vulnerability/wordpress-nirvana-theme-2-6-local-file-inclusion-vulnerability.
I think it’s a misunderstanding due to a template name being the same.
I have your Nirvana theme (latest version 1.6.5),
The Patchstack website instead refers to the Nirvana theme by Axiomthemes (latest version 2.)
I tried contacting Solid Security support but received no response…
Have you received any other reports?
Thanks