Uncode WordPress Theme Arbitrary File Read Vulnerability

Vulnerability

A vulnerability allowing arbitrary file read has been identified in the Uncode theme for WordPress, affecting all versions prior to and including 2.9.1.6. The issue arises from inadequate input validation in the 'uncode_recordMedia' function, enabling authenticated attackers with Subscriber-level access or higher to read arbitrary files from the server.

Impact

Exploitation of this vulnerability could lead to unauthorized access to sensitive files on the server.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
1.0
impact
2.5
exploitability
5.4
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.