Executive brief
The Emphires theme for WordPress contains a security flaw that allows an attacker to access sensitive files on the web server. By exploiting this vulnerability, a malicious user could view internal configuration files, such as those containing database credentials, potentially leading to a full site takeover. This affects websites using version 3.9 or earlier of the theme.
Technical details
A Local File Inclusion (LFI) vulnerability exists in the Creatives_Planet Emphires theme (versions <= 3.9) due to improper validation of user-supplied input used in PHP include or require statements (CWE-98). An attacker with 'Contributor' level privileges can exploit this flaw to include and execute local files on the server. This can lead to the disclosure of sensitive information, such as the wp-config.php file, or potentially remote code execution if the attacker can upload or find a way to influence the contents of a local file. The attack requires network access and authenticated 'Contributor' permissions, with a high complexity (AC:H) noted in the CVSS vector. As of the advisory date, no official patch is available.
Affected products
- Creatives_Planet Emphires <= 3.9
Timeline
- 2026-01-20: other: Vulnerability reported by researcher João Pedro S Alcântara
- 2026-02-19: advisory: Initial disclosure by Patchstack
- 2026-04-08: disclosed: CVE published to NVD