Unauthenticated Local File Inclusion in Resido Theme by Patchstack
CVE-2026-73387
8.1HIGH
What is CVE-2026-73387?
The Resido theme for WordPress is susceptible to an unauthenticated Local File Inclusion (LFI) vulnerability that affects versions up to 1.5. This weakness allows attackers to exploit the theme's improper handling of user input, potentially enabling them to access sensitive files on the server. The exploitation of this vulnerability could lead to unauthorized access and manipulation of critical system files, heightening the risk of further compromise. It is essential for users to upgrade to the latest version to safeguard their websites from potential threats.
Affected Version(s)
Resido <= 1.5
References
CVSS V3.1
Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
João Pedro S Alcântara (Kinorth) | Patchstack Bug Bounty Program