Junglewise Threat Intelligence

CVE-2026-39559: codesupplyco Uppercase Local File Inclusion

CVE-2026-39559 · Severity: high · CVSS 8.1 · Published 2026-06-17

Vendors: Code Supply Co..

Executive brief

The Uppercase theme for WordPress is vulnerable to a security flaw that allows unauthorized users to access sensitive files on the web server. By exploiting this, an attacker could view configuration files containing database credentials, potentially leading to a full takeover of the website and its data. Website administrators should update the theme to version 1.2.2 or later immediately to resolve this risk.

Technical details

A Local File Inclusion (LFI) vulnerability exists in the Uppercase theme for WordPress (versions < 1.2.2) due to improper control of filenames in PHP include/require statements (CWE-98). An unauthenticated remote attacker can exploit this by sending crafted requests to include local files from the server. Successful exploitation can lead to the disclosure of sensitive information, such as the wp-config.php file, which contains database credentials and security keys. While the attack vector is network-based and requires no privileges, the CVSS assessment indicates high complexity, likely due to specific environmental requirements or configuration needs to trigger the inclusion. The issue is resolved in version 1.2.2.

Affected products

  • codesupplyco Uppercase < 1.2.2

Timeline

  • 2026-02-07: other: Vulnerability reported by researcher João Pedro S Alcântara
  • 2026-04-08: advisory: Initial advisory published by Patchstack
  • 2026-06-17: disclosed: CVE published to NVD

References