PHP Local File Inclusion Vulnerability in KuteThemes Boutique Theme
CVE-2026-39613

7.5HIGH

Key Information:

Vendor

WordPress

Status
Vendor
CVE Published:
8 April 2026

What is CVE-2026-39613?

The KuteThemes Boutique theme has a PHP Local File Inclusion vulnerability, allowing remote attackers to include arbitrary files via manipulated parameters. Affected versions are those from n/a up to and including 2.3.3, which potentially exposes sensitive data and the entire server to unauthorized access. It is crucial for users of this theme to update their installations to mitigate this security risk.

Affected Version(s)

Boutique 0 <= 2.3.3

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

João Pedro S Alcântara (Kinorth) | Patchstack Bug Bounty Program
.