Junglewise Threat Intelligence

CVE-2026-42382: Elated-Themes Audrey Theme local file inclusion

CVE-2026-42382 · Severity: high · CVSS 8.1 · Published 2026-07-02

Vendors: Elated-Themes.

Executive brief

The Audrey theme for WordPress is vulnerable to a security flaw that allows unauthorized users to access sensitive files on the web server. By exploiting this, an attacker could view configuration files containing database credentials, potentially leading to a full takeover of the website and its data. There is currently no official patch available from the developer, posing a significant risk to sites using this theme.

Technical details

A Local File Inclusion (LFI) vulnerability exists in the Elated-Themes Audrey theme for WordPress through version 1.5. The flaw stems from improper control of filenames for include/require statements (CWE-98), allowing an unauthenticated remote attacker to include arbitrary local files from the server. While the attack complexity is rated as high, successful exploitation could lead to the disclosure of sensitive information such as wp-config.php or even remote code execution if the attacker can leverage file wrappers or log poisoning. As of the advisory date, no official patch has been released, and users are advised to use third-party security mitigations.

Affected products

  • Elated-Themes Audrey Theme <= 1.5

Timeline

  • 2026-02-02: other: Vulnerability reported by researcher
  • 2026-06-29: advisory: Patchstack published advisory
  • 2026-07-02: disclosed: CVE published to NVD

References