Executive brief
The Learnify theme for WordPress, used for education and online learning websites, contains a security flaw that allows unauthorized users to access sensitive files on the server. An attacker could use this to steal database credentials or other configuration files, potentially leading to a full takeover of the website. At the time of this report, no official patch has been released by the developer.
Technical details
A Local File Inclusion (LFI) vulnerability exists in the Learnify WordPress theme due to improper control of filenames in PHP include/require statements (CWE-98). The flaw allows an unauthenticated remote attacker to include and execute local files on the server by manipulating input parameters. While the attack complexity is rated as high, a successful exploit could lead to the disclosure of sensitive information such as wp-config.php or the execution of arbitrary code if combined with other techniques. As of the advisory date, no official patch is available, though third-party mitigation rules have been proposed.
Affected products
- ThemeREX Group Learnify <= 1.15.0
Timeline
- 2025-07-23: other: Vulnerability reported by researcher Bonds
- 2026-04-23: advisory: Initial advisory published by Patchstack
- 2026-06-17: disclosed: CVE published in NVD