Junglewise Threat Intelligence

CVE-2026-52707: Mikado-Themes Kastell Local File Inclusion

CVE-2026-52707 · Severity: high · CVSS 8.1 · Published 2026-06-17

Vendors: Mikado-Themes.

Executive brief

The Kastell theme for WordPress, used for building professional websites, contains a security flaw that allows unauthorized users to access sensitive files on the server. An attacker could use this to steal configuration data, such as database passwords, potentially leading to a full takeover of the website. Site owners should update to version 2.0.1 immediately to prevent exploitation.

Technical details

A Local File Inclusion (LFI) vulnerability exists in the Kastell theme for WordPress (versions <= 2.0) due to improper validation of user-supplied path input. An unauthenticated remote attacker can exploit this by sending specially crafted requests to include and execute local files on the server. This can lead to the disclosure of sensitive information, such as wp-config.php, or remote code execution if the attacker can upload or find a controllable file on the system. The vulnerability is addressed in version 2.0.1.

Affected products

  • Mikado-Themes Kastell <= 2.0

Timeline

  • 2025-05-04: other: Vulnerability reported by researcher Bonds
  • 2026-06-12: disclosed: Initial disclosure by Patchstack
  • 2026-06-17: advisory: CVE published in NVD

References