Junglewise Threat Intelligence

CVE-2025-58953: ThemeREX Joly Local File Inclusion in WordPress theme

CVE-2025-58953 · Severity: high · CVSS 8.1 · Published 2026-06-17

Vendors: ThemeREX.

Executive brief

The Joly theme for WordPress is vulnerable to a security flaw that allows unauthorized users to access sensitive files on the web server. By exploiting this vulnerability, an attacker could view configuration files containing database credentials, potentially leading to a full takeover of the website and its data. This issue affects all versions of the theme up to and including 1.22.0.

Technical details

A Local File Inclusion (LFI) vulnerability exists in the ThemeREX Joly theme for WordPress due to improper validation of user-supplied input in PHP include/require statements (CWE-98). An unauthenticated remote attacker can exploit this by sending specially crafted requests to include local files from the server. Successful exploitation can lead to the disclosure of sensitive information, such as the wp-config.php file, or potentially remote code execution if the attacker can upload or influence the content of a local file. The vulnerability is fixed in version 1.23.0.

Affected products

  • ThemeREX Joly <= 1.22.0

Timeline

  • 2025-09-08: other: Reported by Tran Nguyen Bao Khanh (VCI - VNPT Cyber Immunity)
  • 2025-10-08: disclosed: Vulnerability published by Patchstack
  • 2025-10-08: patched: Version 1.23.0 released to address the vulnerability
  • 2026-06-17: advisory: NVD advisory published

References