Executive brief
YOOtheme Pro is a website builder for Joomla and WordPress used by agencies and developers to create professional websites. An authenticated user with elevated privileges can read arbitrary files on the web server through a flaw in the Filesystem source's path filtering mechanism, potentially exposing sensitive configuration files, source code, or other confidential data stored on the server.
Technical details
The vulnerability is a path traversal / arbitrary file read flaw in YOOtheme Pro's Filesystem source component. The root cause is insufficient validation of file path parameters, which allows pattern-matching attacks (glob-based patterns) to bypass intended path restrictions. The attack requires authentication and elevated user privileges. An attacker with these credentials can craft malicious path arguments to read files outside the intended directory scope, leading to disclosure of sensitive files. Fix availability and patch status are not specified in the advisory.
Affected products
- YOOtheme Pro 2.3.0-5.0.40
Timeline
- 2026-08-21: disclosed