Executive brief
The Brook theme for WordPress is vulnerable to a security flaw that could allow an attacker with basic user permissions to access sensitive files on the web server. By exploiting this vulnerability, a malicious actor could potentially view configuration files containing database credentials, which could lead to a full takeover of the website's data and operations. There is currently no official patch available for this issue.
Technical details
A Local File Inclusion (LFI) vulnerability exists in the ThemeMove Brook theme for WordPress (versions <= 2.9.0) due to improper validation of user-supplied input used in PHP include or require statements (CWE-98). An authenticated attacker with at least 'Contributor' level privileges can exploit this flaw to include and execute local files on the server. This can lead to the disclosure of sensitive information, such as the wp-config.php file, or potentially remote code execution if the attacker can upload or manipulate local files. The attack requires network access but is mitigated by a high attack complexity and the requirement for basic authentication. As of the advisory date, no official patch has been released.
Affected products
- ThemeMove Brook <= 2.9.0
Timeline
- 2026-01-04: disclosed: Reported by João Pedro S Alcântara (Kinorth)
- 2026-07-02: advisory: Initial advisory published by Patchstack
- 2026-07-13: advisory: CVE published to NVD dataset