Executive brief
Select-Themes Struktur, a professional WordPress theme, contains a security flaw that could allow an attacker to view sensitive internal files. By exploiting this vulnerability, a malicious user with basic account access could potentially read configuration files containing database credentials. This could lead to a full compromise of the website's data and operations.
Technical details
A Local File Inclusion (LFI) vulnerability exists in the Select-Themes Struktur theme for WordPress (versions up to and including 2.5.1) due to improper validation of user-supplied input used in PHP include or require statements (CWE-98). An attacker with at least 'Contributor' level privileges can exploit this flaw to include and execute local files on the server. This can be used to disclose sensitive information, such as the wp-config.php file, which contains database credentials. The attack requires network access but is mitigated by the requirement for authenticated access and potentially high complexity depending on the specific implementation of the vulnerable component. As of the advisory date, no official patch is available.
Affected products
- Select-Themes Struktur <= 2.5.1
Timeline
- 2026-01-20: disclosed: Reported by João Pedro S Alcântara (Kinorth)
- 2026-07-02: advisory: Patchstack published advisory
- 2026-07-13: advisory: NVD published CVE record