Executive brief
The Malmö theme for WordPress is vulnerable to a security flaw that allows unauthorized individuals to access sensitive files on the web server. By exploiting this vulnerability, an attacker could view configuration files containing database credentials or other private information, potentially leading to a full site takeover. Users should update to version 2.3 or later to secure their websites.
Technical details
A Local File Inclusion (LFI) vulnerability exists in the Malmö WordPress theme due to improper control of filenames in PHP 'include' or 'require' statements (CWE-98). An unauthenticated remote attacker can exploit this by sending crafted requests to include local files from the server's filesystem. Successful exploitation can lead to the disclosure of sensitive information, such as the wp-config.php file, or potentially remote code execution if the attacker can upload or influence the content of a local file. The vulnerability is patched in version 2.3.
Affected products
- Elated-Themes Malmö <= 2.2
Timeline
- 2026-02-02: other: Reported by Tran Nguyen Bao Khanh (VCI - VNPT Cyber Immunity)
- 2026-04-08: disclosed: Vulnerability published by Patchstack
- 2026-06-17: advisory: CVE published in NVD