Junglewise Threat Intelligence

CVE-2026-39611: kutethemes KuteShop Local File Inclusion

CVE-2026-39611 · Severity: high · CVSS 7.5 · Published 2026-04-08

Vendors: KuteThemes.

Executive brief

KuteShop is a WordPress theme used for building e-commerce websites. A security vulnerability in this theme allows an attacker with basic user permissions to access sensitive internal files on the web server. This could lead to the exposure of database credentials, configuration files, and potentially a full takeover of the website and its customer data.

Technical details

A Local File Inclusion (LFI) vulnerability exists in the kutethemes KuteShop theme for WordPress (versions up to and including 4.2.9) due to insufficient validation of user-supplied input used in PHP include or require statements. An attacker with 'Contributor' level privileges can exploit this flaw to include and execute local files on the server. This can be used to read sensitive files such as wp-config.php, which contains database credentials. While the CVSS vector indicates high complexity (AC:H), successful exploitation grants high impact across confidentiality, integrity, and availability. As of the advisory date, no official patch has been released.

Affected products

  • kutethemes KuteShop <= 4.2.9

Timeline

  • 2026-01-09: other: Vulnerability reported by researcher João Pedro S Alcântara
  • 2026-04-08: disclosed: Vulnerability published by Patchstack
  • 2026-04-08: advisory: NVD entry created

References

Related threats