Executive brief
VLThemes Leedo, a WordPress theme used for website design and layout, contains a security vulnerability that could allow an attacker to access sensitive internal files. By exploiting this flaw, a malicious user could potentially view configuration files containing database credentials, leading to a full site takeover. This issue affects all versions of the theme up to and including 3.0.0.
Technical details
A Local File Inclusion (LFI) vulnerability exists in the VLThemes Leedo theme for WordPress due to improper validation of user-supplied input used in PHP include or require statements (CWE-98). An attacker with at least Contributor-level privileges can exploit this vulnerability to include and execute local files on the server. This can lead to the exposure of sensitive information, such as the wp-config.php file, which contains database credentials and security keys. The vulnerability affects all versions up to and including 3.0.0, and as of the advisory date, no official patch has been released.
Affected products
- VLThemes Leedo <= 3.0.0
Timeline
- 2026-01-18: disclosed: Reported by João Pedro S Alcântara (Kinorth)
- 2026-07-02: advisory: Initial advisory published by Patchstack
- 2026-07-13: advisory: NVD publication date