Junglewise Threat Intelligence

CVE-2025-68063: StylemixThemes Splash Theme Local File Inclusion

CVE-2025-68063 · Severity: high · CVSS 7.5 · Published 2026-06-26

Vendors: StylemixThemes.

Executive brief

The Splash theme for WordPress, used primarily for sports-related websites, contains a security flaw that allows users with 'Contributor' level access to view sensitive files on the server. An attacker could use this to steal database credentials or other configuration files, potentially leading to a full site takeover. This issue is resolved by updating the theme to version 4.4.4.

Technical details

A Local File Inclusion (LFI) vulnerability exists in the Splash WordPress theme due to improper validation of user-supplied input used in PHP 'include' or 'require' statements (CWE-98). An attacker with Contributor-level privileges can exploit this flaw to include and execute local files on the server. While the attack complexity is rated as high, successful exploitation could allow the attacker to read sensitive files like wp-config.php or achieve remote code execution if they can upload or find a suitable file to include. The vulnerability is patched in version 4.4.4.

Affected products

  • StylemixThemes Splash - Sport Club WordPress Theme for Basketball, Football, Hockey <= 4.4.3

Timeline

  • 2025-11-03: other: Reported by researcher João Pedro S Alcântara
  • 2026-06-26: advisory: Early warning sent to Patchstack customers
  • 2026-06-26: disclosed: Publicly published by Patchstack and NVD
  • 2026-06-26: patched: Version 4.4.4 released to address the vulnerability

References