Executive brief
The Hitek theme for WordPress is vulnerable to a security flaw that allows unauthorized users to access sensitive files on the web server. By exploiting this vulnerability, an attacker could view internal configuration files, such as those containing database credentials, potentially leading to a full site takeover. This issue affects all versions of the theme prior to 1.8.3.
Technical details
A Local File Inclusion (LFI) vulnerability exists in the xtemos Hitek theme for WordPress due to improper control of filenames in PHP include/require statements (CWE-98). The flaw allows an unauthenticated remote attacker to include and execute local files on the server by manipulating input parameters. While the attack complexity is rated as high, a successful exploit could lead to the disclosure of sensitive information, such as the wp-config.php file, or potentially remote code execution if the attacker can upload or influence the content of local files. The vulnerability is resolved in version 1.8.3.
Affected products
- xtemos Hitek < 1.8.3
Timeline
- 2026-02-10: other: Reported by Tran Nguyen Bao Khanh (VCI - VNPT Cyber Immunity)
- 2026-04-08: disclosed: Initial disclosure by Patchstack
- 2026-06-17: advisory: NVD publication date
- 1.8.3: patched