Executive brief
Elated-Themes Flow, a theme for WordPress websites, contains a security vulnerability that could allow an attacker to access sensitive internal files. By exploiting this flaw, a malicious actor could potentially view configuration files containing database credentials, leading to a full site takeover. The theme has not been updated in over a year, and users are advised to replace it with a supported alternative as no official patch is expected.
Technical details
A Local File Inclusion (LFI) vulnerability exists in the Elated-Themes Flow theme for WordPress due to improper control of filenames in include or require statements (CWE-98). An attacker with low-level 'Contributor' privileges can manipulate input to include local files from the server. This can lead to the disclosure of sensitive information, such as the wp-config.php file, or potentially remote code execution if the attacker can upload or find a controllable file on the system. The vulnerability affects all versions up to and including 1.8. No official patch is available as the software is considered abandoned; security researchers recommend removing the theme.
Affected products
- Elated-Themes Flow <= 1.8
Timeline
- 2026-01-21: disclosed: Reported by João Pedro S Alcântara (Kinorth)
- 2026-07-02: advisory: Patchstack published advisory
- 2026-07-13: advisory: CVE published to NVD dataset