Executive brief
The Case Theme User plugin for WordPress is vulnerable to a security flaw that allows attackers to access sensitive files on the web server. By tricking a user into clicking a malicious link or visiting a specific page, an attacker could potentially steal database credentials or other private configuration data. This could lead to a full takeover of the website's database and compromise of customer information.
Technical details
A Local File Inclusion (LFI) vulnerability exists in the Case Themes Case Theme User plugin for WordPress due to improper control of filenames in include/require statements (CWE-98). The vulnerability allows an unauthenticated attacker to include local files from the server, which could result in the disclosure of sensitive information such as wp-config.php. Exploitation requires user interaction, such as a privileged user clicking a malicious link or visiting a crafted page (AC:H/UI:R). The issue affects all versions prior to 1.0.4, and users are advised to upgrade to version 1.0.4 or later to remediate the flaw.
Affected products
- Case Themes Case Theme User < 1.0.4
Timeline
- 2025-05-31: other: Vulnerability reported by researcher Bonds
- 2025-07-01: advisory: Patchstack published advisory and mitigation rules
- 2026-04-10: disclosed: CVE published to NVD