Executive brief
LiquidThemes Hub Core, a core plugin for the Hub WordPress theme, is vulnerable to a security flaw that allows attackers to access internal server files. By exploiting this vulnerability, an attacker could potentially steal sensitive information such as database credentials or configuration files, leading to a full site takeover. This issue affects all versions of the plugin prior to 6.0.2.
Technical details
A Local File Inclusion (LFI) vulnerability exists in the LiquidThemes Hub Core plugin for WordPress due to improper validation of user-supplied input used in PHP include or require statements (CWE-98). An attacker with low-level privileges (such as a Contributor) can exploit this over the network to include and execute local files on the server. This can lead to the disclosure of sensitive files like wp-config.php or, in some configurations, remote code execution. The vulnerability is addressed in version 6.0.2.
Affected products
- LiquidThemes Hub Core before 6.0.2
Timeline
- 2025-10-10: other: Vulnerability reported by researcher João Pedro S Alcântara
- 2025-11-09: disclosed: Initial disclosure by Patchstack
- 2025-12-16: advisory: NVD publication of CVE-2025-68065
- 2025-12-16: patched: Patch confirmed available in version 6.0.2