Junglewise Threat Intelligence

CVE-2026-39568: Elated-Themes Mr. SEO Local File Inclusion

CVE-2026-39568 · Severity: high · CVSS 8.1 · Published 2026-06-17

Vendors: Elated-Themes.

Executive brief

Mr. SEO is a WordPress theme used for building search engine optimized websites. A security flaw in versions 2.0 and earlier allows unauthenticated attackers to access sensitive internal files on the web server. This could lead to the exposure of database credentials, configuration files, and other private data, potentially resulting in a full site takeover.

Technical details

A Local File Inclusion (LFI) vulnerability exists in the Mr. SEO theme for WordPress (versions <= 2.0) due to improper control of filenames in PHP include/require statements (CWE-98). An unauthenticated remote attacker can exploit this by sending specially crafted requests to include local files from the server's filesystem. Successful exploitation allows the attacker to view the contents of sensitive files, such as wp-config.php, which may contain database credentials. The vulnerability is mitigated in version 2.1.

Affected products

  • Elated-Themes Mr. SEO <= 2.0

Timeline

  • 2026-02-02: other: Reported by Tran Nguyen Bao Khanh (VCI - VNPT Cyber Immunity)
  • 2026-04-08: advisory: Patchstack published advisory
  • 2026-06-17: disclosed: CVE published to NVD

References