Junglewise Threat Intelligence

CVE-2026-57803: Select-Themes Struktur Core Local File Inclusion

CVE-2026-57803 · Severity: high · CVSS 7.5 · Published 2026-07-13

Vendors: Select-Themes.

Executive brief

Select-Themes Struktur Core, a WordPress plugin used for theme functionality, contains a security flaw that could allow an attacker to access sensitive server files. By exploiting this vulnerability, a logged-in user with low-level permissions could potentially view configuration files containing database credentials, leading to a full site or database takeover. This issue affects all versions of the plugin up to and including 2.5.1.

Technical details

A Local File Inclusion (LFI) vulnerability exists in the Select-Themes Struktur Core plugin (struktur-core) for WordPress. The flaw stems from improper validation of user-supplied input used in PHP include or require statements (CWE-98). An attacker with 'Contributor' level privileges or higher can manipulate file paths to include local files from the server's filesystem. This can lead to the disclosure of sensitive information, such as the wp-config.php file, or potentially remote code execution if the attacker can upload or find a controllable file on the server. The vulnerability affects versions up to 2.5.1; as of the advisory date, no official patch has been confirmed.

Affected products

  • Select-Themes Struktur Core (struktur-core) <= 2.5.1

Timeline

  • 2026-01-20: other: Reported by researcher João Pedro S Alcântara
  • 2026-07-02: advisory: Initial disclosure by Patchstack
  • 2026-07-13: disclosed: CVE published to NVD dataset

References