Junglewise Threat Intelligence

CVE-2025-69094: ThemeMove Unicamp SQL injection in WordPress theme

CVE-2025-69094 · Severity: high · CVSS 8.5 · Published 2026-07-02

Vendors: ThemeMove.

Executive brief

The Unicamp theme for WordPress, which is used to build university and education-related websites, contains a security flaw that allows users with basic 'Subscriber' accounts to interfere with the site's database. An attacker could use this to steal sensitive information or disrupt site operations. There is currently no official patch available from the developer, so administrators should consider alternative security mitigations.

Technical details

A SQL injection vulnerability (CWE-89) exists in the ThemeMove Unicamp theme for WordPress through version 2.2.2. The flaw is accessible to authenticated users with Subscriber-level permissions, allowing them to bypass intended input sanitization and interact directly with the underlying database. By sending specially crafted network requests, an attacker can extract sensitive data or cause minor service disruptions. As of the latest advisory, no official patch has been released by the vendor, and users are advised to use web application firewalls or virtual patching solutions.

Affected products

  • ThemeMove Unicamp <= 2.2.2

Timeline

  • 2025-09-21: disclosed: Vulnerability reported by researcher Bonds
  • 2026-06-29: advisory: Patchstack published initial advisory
  • 2026-07-02: advisory: NVD published CVE-2025-69094

References