Junglewise Threat Intelligence

CVE-2026-57800: Edge-Themes Overworld Local File Inclusion

CVE-2026-57800 · Severity: high · CVSS 7.5 · Published 2026-07-13

Vendors: Edge-Themes.

Executive brief

The Overworld theme for WordPress is vulnerable to a security flaw that allows attackers to access sensitive internal files. By exploiting this issue, a malicious user with basic account access could view configuration files containing database credentials or other private system data. This could lead to a full compromise of the website's database and underlying information.

Technical details

A Local File Inclusion (LFI) vulnerability exists in the Edge-Themes Overworld theme (versions up to and including 1.5) due to insufficient validation of user-supplied input used in PHP include or require statements (CWE-98). An attacker with at least 'Contributor' level privileges can exploit this to include and execute local files on the server. This can be used to leak sensitive information, such as the wp-config.php file, which contains database credentials. The attack vector is network-based, though it requires low-level authentication and specific environmental conditions (AC:H). As of the advisory date, no official patch has been released.

Affected products

  • Edge-Themes Overworld <= 1.5

Timeline

  • 2026-01-23: disclosed: Reported by João Pedro S Alcântara (Kinorth)
  • 2026-07-02: advisory: Patchstack published the vulnerability details
  • 2026-07-13: advisory: NVD published the CVE record

References