Executive brief
VideoPro is a WordPress theme used for building video-sharing websites. A security flaw allows unauthorized individuals to access sensitive internal files on the web server. This could lead to the exposure of database credentials, configuration files, and other private data, potentially resulting in a full takeover of the website.
Technical details
A Local File Inclusion (LFI) vulnerability exists in the CactusThemes VideoPro theme for WordPress due to improper control of filenames in include or require statements (CWE-98). An unauthenticated remote attacker can exploit this by providing malicious input to vulnerable parameters, forcing the application to include and execute local files. While the CVSS vector indicates high complexity (AC:H), successful exploitation allows the attacker to read sensitive files like wp-config.php, which contains database credentials. As of the advisory date, no official patch has been released by the vendor, and users are advised to use third-party mitigation rules.
Affected products
- CactusThemes VideoPro <= 2.3.8.1
Timeline
- 2025-09-18: other: Vulnerability reported by researcher
- 2026-01-08: advisory: Patchstack published initial advisory
- 2026-04-10: disclosed: CVE published to NVD