Junglewise Threat Intelligence

CVE-2026-39552: Code Supply Co. Blueprint Local File Inclusion in WordPress theme

CVE-2026-39552 · Severity: high · CVSS 8.1 · Published 2026-06-02

Vendors: Code Supply Co..

Executive brief

The Blueprint theme for WordPress contains a security flaw that allows unauthorized users to access sensitive files on the web server. By exploiting this vulnerability, an attacker could view internal configuration files, potentially exposing database credentials and leading to a full takeover of the website. This issue affects all versions of the theme prior to 1.1.5.

Technical details

A Local File Inclusion (LFI) vulnerability exists in the Code Supply Co. Blueprint theme for WordPress due to improper validation of user-supplied input used in PHP include or require statements (CWE-98). An unauthenticated remote attacker can exploit this by submitting specially crafted requests to include local files from the server's filesystem. Successful exploitation can lead to the disclosure of sensitive information, such as the wp-config.php file containing database credentials, or potentially remote code execution if the attacker can upload or find a controllable file on the system. The vulnerability is addressed in version 1.1.5.

Affected products

  • Code Supply Co. Blueprint before 1.1.5

Timeline

  • 2026-02-07: other: Vulnerability reported by researcher João Pedro S Alcântara
  • 2026-04-08: advisory: Patchstack published initial advisory
  • 2026-06-02: disclosed: CVE published to NVD
  • 2026-06-02: patched: Fix available in version 1.1.5

References