Executive brief
The Planty theme for WordPress is vulnerable to a security flaw that allows unauthorized individuals to access sensitive files on the web server. By exploiting this vulnerability, an attacker could view configuration files containing database credentials or other private information, potentially leading to a full takeover of the website. There is currently no official patch available from the developer.
Technical details
A Local File Inclusion (LFI) vulnerability exists in the ThemeREX Planty theme for WordPress through version 1.14.0. The flaw is classified under CWE-98 (Improper Control of Filename for Include/Require Statement) and allows an unauthenticated remote attacker to include local files from the server. While the attack complexity is rated as high, successful exploitation can lead to the disclosure of sensitive system files (such as wp-config.php) or remote code execution if combined with other techniques like log poisoning. As of the advisory date, no official patch has been released, and users are advised to seek alternative mitigation strategies.
Affected products
- ThemeREX Planty <= 1.14.0
Timeline
- 2025-10-15: other: Vulnerability reported by Tran Nguyen Bao Khanh (VCI - VNPT Cyber Immunity)
- 2026-05-26: advisory: Patchstack published advisory details
- 2026-06-17: disclosed: NVD published CVE-2025-69112