What the vulnerability does
01Description
The Uncode theme for WordPress is vulnerable to arbitrary file read due to insufficient input validation in the 'uncode_recordMedia' function in all versions up to, and including, 2.9.1.6. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read arbitrary files on the server.
Explanation of Vulnerability in Simple Terms
02Summary
Uncode versions up to 2.9.1.6 contain an improper input validation flaw that allows authenticated users to read sensitive data they should not have access to. The vulnerability requires a valid user account but no special privileges. An attacker with low-level access can extract confidential information from the application without modifying or disrupting service.
What an attacker can do
03Attacker Capabilities
Read sensitive data or information they should not have access to.
Potential impact on your site
04Site Impact
User data confidentiality is at risk; authenticated attackers can access information beyond their permission level.
Conditions required to exploit
05Prerequisites
Attacker must have a valid user account with low-level privileges.
Key dates
06Disclosure timeline
February 18, 2025
CVE published
April 8, 2026
Record updated