Junglewise Threat Intelligence

CVE-2026-39538: Mikado-Themes Mikado Core local file inclusion

CVE-2026-39538 · Severity: high · CVSS 7.5 · Published 2026-04-08

Vendors: Mikado-Themes.

Executive brief

Mikado Core is a foundational WordPress plugin used by various Mikado-Themes to provide core functionality. A security flaw in this plugin allows an attacker with basic contributor-level access to view sensitive internal files on the web server. This could lead to the exposure of database credentials or other configuration data, potentially resulting in a full site takeover.

Technical details

A Local File Inclusion (LFI) vulnerability exists in the Mikado Core plugin (mikado-core) for WordPress due to insufficient validation of user-supplied input used in PHP include or require statements (CWE-98). The flaw allows an authenticated attacker with 'Contributor' or higher privileges to manipulate file paths and include arbitrary local files from the server. Successful exploitation can lead to the disclosure of sensitive information, such as the wp-config.php file containing database credentials. The vulnerability is present in versions up to and including 1.6 and is addressed in version 2.2.2.

Affected products

  • Mikado-Themes Mikado Core <= 1.6

Timeline

  • 2026-01-03: other: Vulnerability reported by researcher
  • 2026-02-02: disclosed: Initial disclosure by Patchstack
  • 2026-04-08: advisory: CVE published to NVD
  • 2026-02-02: patched: Patch released in version 2.2.2

References

Related threats