Junglewise Threat Intelligence

CVE-2026-57788: Edge-Themes Aalto Local File Inclusion

CVE-2026-57788 · Severity: high · CVSS 7.5 · Published 2026-07-13

Vendors: Edge-Themes.

Executive brief

Aalto, a professional WordPress theme used for building websites, contains a security vulnerability that could allow an attacker to access sensitive internal files. By exploiting this flaw, a malicious user with basic account access could potentially view configuration files containing database credentials or other private information. This could lead to a full compromise of the website's data and operations.

Technical details

A Local File Inclusion (LFI) vulnerability exists in the Edge-Themes Aalto theme for WordPress (versions up to and including 1.8) due to insufficient validation of user-supplied input used in PHP include or require statements (CWE-98). An attacker with 'Contributor' level privileges can exploit this vulnerability to include and execute local files on the server. This can lead to the disclosure of sensitive information, such as the wp-config.php file containing database credentials, or potentially remote code execution if the attacker can upload or manipulate local files. The attack requires network access and a low-privileged account. As of the advisory date, no official patch is available.

Affected products

  • Edge-Themes Aalto <= 1.8

Timeline

  • 2026-01-22: other: Vulnerability reported by researcher João Pedro S Alcântara
  • 2026-07-02: disclosed: Vulnerability disclosed by Patchstack
  • 2026-07-13: advisory: CVE published in NVD dataset

References