Junglewise Threat Intelligence

CVE-2026-11426: WebFactory UnderConstructionPage PRO arbitrary file read in template_thumbnail

CVE-2026-11426 · Severity: medium · CVSS 6.5 · Published 2026-07-11

Executive brief

The UnderConstructionPage PRO plugin for WordPress, which helps site owners create maintenance and landing pages, contains a security flaw that allows users with low-level accounts (like subscribers) to read sensitive files from the web server. This could lead to the exposure of configuration files, passwords, or other private data. The issue occurs because the plugin incorrectly handles file path requests, allowing an attacker to copy internal server files into a publicly accessible folder.

Technical details

The UnderConstructionPage PRO plugin for WordPress is vulnerable to an Arbitrary File Read vulnerability (CWE-22) in all versions up to and including 5.76. The root cause is the plugin's failure to validate local file paths provided in the 'template_thumbnail' parameter; it accepts arbitrary paths and copies the target file's contents into a publicly accessible directory within the WordPress uploads folder. An authenticated attacker with Subscriber-level permissions or higher can exploit this to retrieve sensitive files from the server, such as wp-config.php. The vulnerability was addressed in version 5.81.

Affected products

  • WebFactory Under Construction Page (Pro) 0 - 5.76

Timeline

  • 2026-07-07: patched: Version 5.81 released with security fixes.
  • 2026-07-10: disclosed: Vulnerability reported by Wordfence.
  • 2026-07-11: advisory: NVD published the CVE record.

References