Executive brief
The Cookiteer theme for WordPress is vulnerable to a security flaw that allows attackers to access sensitive files on the web server. By exploiting this, an attacker could steal database credentials or other configuration files, potentially leading to a full takeover of the website and its data. There is currently no official patch available from the developer.
Technical details
A Local File Inclusion (LFI) vulnerability exists in the androThemes Cookiteer theme (versions up to 1.4.8) due to improper control of filenames in PHP include/require statements (CWE-98). An unauthenticated remote attacker can exploit this by sending a specially crafted request to include local files from the server. Successful exploitation could allow the attacker to read sensitive files such as wp-config.php, potentially leading to full site compromise or remote code execution if combined with other techniques. The attack complexity is rated as high, and as of the advisory date, no official patch has been released.
Affected products
- androThemes Cookiteer n/a through 1.4.8
Timeline
- 2025-12-04: other: Vulnerability reported by researcher
- 2026-03-03: advisory: Patchstack published advisory
- 2026-06-02: disclosed: NVD publication date