Executive brief
Thegov Core, a WordPress plugin used for municipal and government website themes, contains a security flaw that allows unauthorized users to access sensitive files on the server. An attacker could use this to view configuration files containing database credentials or other private system data. This could lead to a full takeover of the website and its underlying database.
Technical details
Thegov Core plugin for WordPress (versions prior to 2.0.23) is vulnerable to Local File Inclusion (LFI) due to improper control of filenames in PHP include/require statements (CWE-98). An unauthenticated remote attacker can exploit this vulnerability to include and execute local files on the server. While the CVSS vector indicates high complexity (AC:H), successful exploitation allows for the disclosure of sensitive information such as wp-config.php, which contains database credentials. This can lead to unauthorized data access or full site compromise. The issue is resolved in version 2.0.23.
Affected products
- WebGeniusLab Thegov Core < 2.0.23
Timeline
- 2026-02-07: other: Reported by researcher João Pedro S Alcântara (Kinorth)
- 2026-04-07: disclosed: Initial disclosure by Patchstack
- 2026-06-17: advisory: NVD publication date