Junglewise Threat Intelligence

CVE-2026-57793: Elated-Themes Flow Local File Inclusion

CVE-2026-57793 · Severity: high · CVSS 7.5 · Published 2026-07-13

Vendors: Elated-Themes.

Executive brief

Elated-Themes Flow, a theme for WordPress websites, contains a security vulnerability that could allow an attacker to access sensitive internal files. By exploiting this flaw, a malicious actor could potentially view configuration files containing database credentials, leading to a full site takeover. The theme has not been updated in over a year, and users are advised to replace it with a supported alternative as no official patch is expected.

Technical details

A Local File Inclusion (LFI) vulnerability exists in the Elated-Themes Flow theme for WordPress due to improper control of filenames in include or require statements (CWE-98). An attacker with low-level 'Contributor' privileges can manipulate input to include local files from the server. This can lead to the disclosure of sensitive information, such as the wp-config.php file, or potentially remote code execution if the attacker can upload or find a controllable file on the system. The vulnerability affects all versions up to and including 1.8. No official patch is available as the software is considered abandoned; security researchers recommend removing the theme.

Affected products

  • Elated-Themes Flow <= 1.8

Timeline

  • 2026-01-21: disclosed: Reported by João Pedro S Alcântara (Kinorth)
  • 2026-07-02: advisory: Patchstack published advisory
  • 2026-07-13: advisory: CVE published to NVD dataset

References