Junglewise Threat Intelligence

CVE-2026-39590: ThemeMove Atomlab Local File Inclusion

CVE-2026-39590 · Severity: high · CVSS 8.1 · Published 2026-06-17

Vendors: ThemeMove.

Executive brief

Atomlab, a professional WordPress theme used for building business websites, contains a security flaw that allows unauthorized users to access sensitive internal files. An attacker could exploit this to steal configuration data, such as database passwords, potentially leading to a full takeover of the website and its data. This vulnerability is considered high priority as it can be exploited remotely without any login credentials.

Technical details

A Local File Inclusion (LFI) vulnerability exists in the ThemeMove Atomlab theme for WordPress through version 2.4.5. The flaw stems from improper control of filenames in PHP 'include' or 'require' statements (CWE-98), allowing an unauthenticated attacker to specify local files for execution or display. While the CVSS vector indicates high complexity (AC:H), a successful exploit enables the attacker to retrieve sensitive information like wp-config.php or system files, which can lead to remote code execution or full site compromise. The issue is resolved in version 2.4.6.

Affected products

  • ThemeMove Atomlab <= 2.4.5

Timeline

  • 2026-02-20: other: Reported by researcher João Pedro S Alcântara (Kinorth)
  • 2026-04-20: disclosed: Initial disclosure by Patchstack
  • 2026-06-17: advisory: NVD publication date

References