Junglewise Threat Intelligence

CVE-2026-75115: YOOtheme Pro arbitrary file read in Filesystem source

CVE-2026-75115 · Severity: info · Published 2026-08-21

Vendors: YOOtheme.

Executive brief

YOOtheme Pro is a website builder for Joomla and WordPress used by agencies and developers to create professional websites. An authenticated user with elevated privileges can read arbitrary files on the web server through a flaw in the Filesystem source's path filtering mechanism, potentially exposing sensitive configuration files, source code, or other confidential data stored on the server.

Technical details

The vulnerability is a path traversal / arbitrary file read flaw in YOOtheme Pro's Filesystem source component. The root cause is insufficient validation of file path parameters, which allows pattern-matching attacks (glob-based patterns) to bypass intended path restrictions. The attack requires authentication and elevated user privileges. An attacker with these credentials can craft malicious path arguments to read files outside the intended directory scope, leading to disclosure of sensitive files. Fix availability and patch status are not specified in the advisory.

Affected products

  • YOOtheme Pro 2.3.0-5.0.40

Timeline

  • 2026-08-21: disclosed

References