Executive brief
Mikado-Themes Dør, a premium WordPress theme, is vulnerable to a security flaw that could allow an attacker to view sensitive internal files. By exploiting this vulnerability, a malicious user with basic account access could potentially read configuration files containing database credentials or other private system information. This could lead to a full compromise of the website's data and operations.
Technical details
A Local File Inclusion (LFI) vulnerability exists in the Mikado-Themes Dør theme for WordPress through version 2.4.1. The issue stems from improper validation of user-supplied input used in PHP include or require statements (CWE-98). An attacker with at least 'Contributor' level privileges can exploit this to include arbitrary local files from the server's filesystem. Successful exploitation could result in the disclosure of sensitive information, such as the wp-config.php file, potentially leading to remote code execution or full database takeover. As of the advisory date, no official patch has been released.
Affected products
- Mikado-Themes Dør <= 2.4.1
Timeline
- 2026-01-06: disclosed: Reported by João Pedro S Alcântara (Kinorth)
- 2026-07-02: advisory: Patchstack published advisory
- 2026-07-13: advisory: NVD published CVE-2026-57792