Executive brief
Select-Themes SetSail, a WordPress theme designed for travel and booking websites, contains a security vulnerability that could allow an attacker to access sensitive internal files. By exploiting this flaw, an authorized user with low-level permissions could potentially view configuration files containing database credentials, leading to a full site takeover. There is currently no official patch available for this issue.
Technical details
A Local File Inclusion (LFI) vulnerability exists in the Select-Themes SetSail theme for WordPress through version 2.1. The flaw stems from improper validation of user-supplied input used in PHP include or require statements (CWE-98). An attacker with at least 'Contributor' level privileges can manipulate file paths to include local files from the server. This can lead to the disclosure of sensitive information, such as the wp-config.php file, which contains database credentials. As of the advisory date, no official patch has been released by the vendor.
Affected products
- Select-Themes SetSail <= 2.1
Timeline
- 2026-01-20: disclosed: Vulnerability reported by João Pedro S Alcântara (Kinorth)
- 2026-07-02: advisory: Patchstack published advisory details
- 2026-07-13: advisory: CVE published to NVD dataset