Junglewise Threat Intelligence

CVE-2026-39661: Magentech SW Core Local File Inclusion in WordPress plugin

CVE-2026-39661 · Severity: high · CVSS 7.5 · Published 2026-05-26

Executive brief

Magentech SW Core, a WordPress plugin used for theme functionality, contains a security flaw that could allow an attacker to access sensitive files on the web server. By exploiting this vulnerability, a malicious actor could read configuration files containing database credentials, potentially leading to a full site takeover or data breach. This issue affects all versions of the plugin up to 1.7.18.

Technical details

A Local File Inclusion (LFI) vulnerability exists in the Magentech SW Core plugin for WordPress (versions up to 1.7.18) due to insufficient validation of user-supplied input used in PHP include or require statements (CWE-98). An attacker with at least 'Contributor' level privileges can exploit this flaw to include and execute local files on the server. This can lead to the disclosure of sensitive information, such as the wp-config.php file, or potentially remote code execution if the attacker can upload or influence the content of a local file. The attack requires network access but is mitigated by a high attack complexity and the requirement for authenticated access. As of the advisory date, no official patch is available.

Affected products

  • Magentech SW Core <= 1.7.18

Timeline

  • 2026-01-18: disclosed: Reported by João Pedro S Alcântara (Kinorth)
  • 2026-05-26: advisory: Published by Patchstack and NVD

References