Executive brief
The LabtechCO WordPress theme is vulnerable to a security flaw that allows authenticated users to access sensitive files on the web server. By exploiting this vulnerability, an attacker could view internal configuration files, such as those containing database credentials, potentially leading to a full site takeover. This affects websites using version 8.3 or earlier of the theme.
Technical details
A Local File Inclusion (LFI) vulnerability exists in the themeStek LabtechCO theme for WordPress (versions <= 8.3) due to improper validation of user-supplied input used in PHP include or require statements (CWE-98). An attacker with 'Contributor' level privileges or higher can manipulate file paths to include and execute local files on the server. This can lead to the disclosure of sensitive information, such as wp-config.php, or potentially remote code execution if the attacker can upload or find a controllable file on the filesystem. The issue is resolved in version 8.4.
Affected products
- themeStek LabtechCO <= 8.3
Timeline
- 2026-01-20: other: Vulnerability reported by researcher
- 2026-02-19: advisory: Patchstack published advisory
- 2026-04-08: disclosed: CVE published
- 2026-06-17: patched: Vendor released version 8.4 to address the issue