Junglewise Threat Intelligence

CVE-2026-39613: kutethemes Boutique Local File Inclusion in WordPress theme

CVE-2026-39613 · Severity: high · CVSS 7.5 · Published 2026-04-08

Vendors: KuteThemes.

Executive brief

The Boutique theme for WordPress contains a security flaw that could allow an attacker to access sensitive internal files. By exploiting this vulnerability, a malicious actor could view configuration files containing database credentials, potentially leading to a full takeover of the website and its data. This affects online stores and websites using the Boutique theme version 2.3.3 and earlier.

Technical details

A Local File Inclusion (LFI) vulnerability exists in the kutethemes Boutique (kute-boutique) theme for WordPress through version 2.3.3. The flaw stems from improper validation of user-supplied input used in PHP include or require statements (CWE-98). An authenticated attacker with 'Contributor' level privileges can exploit this to include and execute local files on the server. This can lead to the disclosure of sensitive information, such as the wp-config.php file, or potentially remote code execution if the attacker can upload or find a way to influence the contents of a local file. As of the advisory date, no official patch has been released.

Affected products

  • kutethemes Boutique (kute-boutique) <= 2.3.3

Timeline

  • 2026-01-11: other: Vulnerability reported by researcher
  • 2026-02-10: disclosed: Initial disclosure by Patchstack
  • 2026-04-08: advisory: CVE published to NVD

References