CVE-2026-52707
Deferred Deferred - Pending Action
Unauthenticated Local File Inclusion in Kastell <= 2.0

Publication date: 2026-06-17

Last updated on: 2026-06-17

Assigner: Patchstack

Description
Unauthenticated Local File Inclusion in Kastell <= 2.0 versions.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-17
Last Modified
2026-06-17
Generated
2026-06-17
AI Q&A
2026-06-17
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Showing 3 associated CPEs
Vendor Product Version / Range
kastell kastell to 2.0 (inc)
patchstack kastell to 2.0 (exc)
patchstack kastell From 2.0.1 (inc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-35 The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize '.../...//' (doubled triple dot slash) sequences that can resolve to a location that is outside of that directory.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

The WordPress Kastell Theme, versions 2.0 and below, contains a high-priority Local File Inclusion (LFI) vulnerability. This flaw allows attackers to include local files on the target website without needing any authentication.

Exploiting this vulnerability can expose sensitive data such as database credentials and may lead to a full database takeover depending on the site's configuration.

This vulnerability is categorized under the OWASP Top 10 category A3: Injection.

Impact Analysis

This vulnerability can have severe impacts including exposure of sensitive information like database credentials.

Attackers could potentially take over the entire database of the affected website, leading to data loss, data manipulation, or further compromise of the system.

Since the vulnerability is unauthenticated, attackers do not need prior access, increasing the risk and ease of exploitation.

Mitigation Strategies

Immediate action is recommended to mitigate the Local File Inclusion vulnerability in Kastell versions 2.0 and below.

  • Update the Kastell theme to version 2.0.1 or later, which resolves the issue.
  • Apply the mitigation rule provided by Patchstack to block attacks until the update can be applied.
Compliance Impact

The vulnerability allows unauthenticated attackers to include local files on the target website, potentially exposing sensitive data such as database credentials and enabling full database takeover depending on the site's configuration.

Exposure of sensitive data due to this vulnerability could lead to non-compliance with data protection regulations like GDPR and HIPAA, which require safeguarding personal and sensitive information against unauthorized access.

Therefore, exploitation of this vulnerability may result in violations of these standards, as it compromises confidentiality, integrity, and availability of sensitive data.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-52707. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart