CVE-2026-22499
8.1Elated-Themes · Lella
The Elated-Themes Lella WordPress theme is susceptible to a local file inclusion vulnerability due to improper control of filenames in include or require statements.
Executive summary
A critical local file inclusion vulnerability in the Elated-Themes Lella WordPress theme allows unauthenticated attackers to potentially read sensitive files or execute arbitrary code on the server.
Vulnerability
This is a local file inclusion (CWE-98) flaw where the application fails to properly sanitize input used in file inclusion functions. The vulnerability is exploitable by unauthenticated remote attackers.
Business impact
The ability to perform local file inclusion poses a severe threat to business operations, as it may allow unauthorized actors to access sensitive configuration files, database credentials, or system source code. With a CVSS score of 8.1, this vulnerability indicates a high potential for total system compromise, which could lead to significant data breaches, loss of customer trust, and extended service downtime.
Remediation
Immediate Action: As no specific patch version is currently identified, administrators should immediately deactivate or remove the Lella theme if it is not business-critical.
Proactive Monitoring: Review web server access logs for requests containing suspicious directory traversal patterns or unexpected file path inclusions.
Compensating Controls: Implement a Web Application Firewall (WAF) rule to block requests that include directory traversal sequences or attempt to access sensitive system files via theme parameters.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Given the high severity of this file inclusion vulnerability, security teams must prioritize the isolation of affected systems. Until a vendor-supplied update is available, removing or disabling the vulnerable Lella theme remains the most effective method to prevent unauthorized access and potential remote code execution.
More Elated-Themes CVEs
Sources
Originally found and disclosed by Tran Nguyen Bao Khanh (VCI - VNPT Cyber Immunity) | Patchstack Bug Bounty Program, per the CVE Program record.