Junglewise Threat Intelligence

CVE-2025-68065: LiquidThemes Hub Core local file inclusion

CVE-2025-68065 · Severity: high · CVSS 7.5 · Published 2025-12-16

Executive brief

LiquidThemes Hub Core, a core plugin for the Hub WordPress theme, is vulnerable to a security flaw that allows attackers to access internal server files. By exploiting this vulnerability, an attacker could potentially steal sensitive information such as database credentials or configuration files, leading to a full site takeover. This issue affects all versions of the plugin prior to 6.0.2.

Technical details

A Local File Inclusion (LFI) vulnerability exists in the LiquidThemes Hub Core plugin for WordPress due to improper validation of user-supplied input used in PHP include or require statements (CWE-98). An attacker with low-level privileges (such as a Contributor) can exploit this over the network to include and execute local files on the server. This can lead to the disclosure of sensitive files like wp-config.php or, in some configurations, remote code execution. The vulnerability is addressed in version 6.0.2.

Affected products

  • LiquidThemes Hub Core before 6.0.2

Timeline

  • 2025-10-10: other: Vulnerability reported by researcher João Pedro S Alcântara
  • 2025-11-09: disclosed: Initial disclosure by Patchstack
  • 2025-12-16: advisory: NVD publication of CVE-2025-68065
  • 2025-12-16: patched: Patch confirmed available in version 6.0.2

References