Junglewise Threat Intelligence

CVE-2025-69105: ThemeREX Modernee Local File Inclusion

CVE-2025-69105 · Severity: high · CVSS 8.1 · Published 2026-06-17

Vendors: ThemeREX.

Executive brief

The Modernee theme for WordPress is vulnerable to a security flaw that allows unauthorized individuals to access sensitive internal files. By exploiting this, an attacker could potentially view configuration files containing database credentials, leading to a full takeover of the website and its data. At the time of this advisory, no official patch has been released by the developer.

Technical details

A Local File Inclusion (LFI) vulnerability exists in the ThemeREX Modernee theme for WordPress (versions <= 1.6.0) due to improper control of filenames in PHP include/require statements (CWE-98). An unauthenticated remote attacker can exploit this by sending specially crafted requests to include local files from the server. Successful exploitation can lead to the disclosure of sensitive information, such as wp-config.php, or potentially remote code execution if combined with other techniques like log file poisoning. As of the reporting date, no official patch is available, though third-party mitigation rules have been proposed.

Affected products

  • ThemeREX Modernee <= 1.6.0

Timeline

  • 2025-10-15: other: Vulnerability reported by researcher
  • 2026-05-26: advisory: Patchstack published advisory
  • 2026-06-17: disclosed: CVE published to NVD

References