Junglewise Threat Intelligence

CVE-2026-39547: Select-Themes Getaway Local File Inclusion

CVE-2026-39547 · Severity: high · CVSS 8.1 · Published 2026-06-17

Vendors: Select-Themes.

Executive brief

The Getaway theme for WordPress is vulnerable to a security flaw that allows unauthorized individuals to access sensitive files on the web server. By exploiting this vulnerability, an attacker could potentially view configuration files containing database credentials, leading to a full takeover of the website and its data. This issue affects all versions of the theme prior to 1.8, and site owners are advised to update immediately to prevent unauthorized access.

Technical details

A Local File Inclusion (LFI) vulnerability exists in the Getaway theme for WordPress due to improper control of filenames in PHP include/require statements (CWE-98). An unauthenticated remote attacker can exploit this by sending specially crafted requests to the server, forcing the application to include and execute local files. This can lead to the disclosure of sensitive information, such as the wp-config.php file containing database credentials, or potentially remote code execution if the attacker can upload or influence the contents of a local file. The vulnerability is fixed in version 1.8.

Affected products

  • Select-Themes Getaway < 1.8

Timeline

  • 2026-02-06: other: Vulnerability reported by researcher João Pedro S Alcântara
  • 2026-04-08: disclosed: Initial disclosure by Patchstack
  • 2026-06-17: advisory: NVD publication date

References