Junglewise Threat Intelligence

CVE-2026-57799: uxper Nuss Local File Inclusion in WordPress theme

CVE-2026-57799 · Severity: high · CVSS 7.5 · Published 2026-07-13

Executive brief

The Nuss theme for WordPress is vulnerable to a security flaw that could allow an attacker to access sensitive internal files. By exploiting this vulnerability, a malicious user could potentially view configuration files containing database credentials, leading to a full takeover of the website's data and operations. This affects websites using the Nuss theme version 1.3.6 and earlier.

Technical details

A Local File Inclusion (LFI) vulnerability exists in the uxper Nuss theme for WordPress (versions <= 1.3.6) due to insufficient validation of user-supplied input used in PHP include or require statements (CWE-98). An attacker with 'Contributor' level privileges can exploit this flaw to include and execute local files on the server. This can lead to the disclosure of sensitive information, such as the wp-config.php file containing database credentials, or potentially remote code execution if the attacker can upload or find a way to influence the contents of a local file. The attack requires network access and a low-privileged account, though the complexity is rated as high. As of the advisory date, no official patch has been released.

Affected products

  • uxper Nuss <= 1.3.6

Timeline

  • 2026-01-06: other: Vulnerability reported by researcher
  • 2026-07-02: advisory: Patchstack published advisory
  • 2026-07-13: disclosed: CVE published to NVD

References