Junglewise Threat Intelligence

CVE-2026-76613: YOOtheme Pro SQL injection in contributor functionality

CVE-2026-76613 · Severity: info · Published 2026-08-21

Vendors: YOOtheme.

Executive brief

YOOtheme Pro is a popular website builder extension for Joomla and WordPress used by designers and developers. This vulnerability allows any contributor-level user to inject malicious SQL commands into database queries, potentially leading to unauthorized data access, modification, or deletion depending on database permissions and the attacker's objectives.

Technical details

This is an authenticated SQL injection vulnerability in YOOtheme Pro versions 1.0.0 through 5.0.40. A contributor-level user (a lower privilege role, typically one step above anonymous) can craft malicious input that is directly injected into SQL queries without proper sanitization or parameterization. The vulnerability requires authentication as a contributor or higher, but does not require administrator privileges. Successful exploitation allows an attacker to read, modify, or delete database records depending on the database user's permissions and the context of the vulnerable query.

Affected products

  • YOOtheme Pro 1.0.0-5.0.40

Timeline

  • 2026-08-21: disclosed

References