Junglewise Threat Intelligence

CVE-2025-69117: ThemeREX Ingenioso local file inclusion

CVE-2025-69117 · Severity: high · CVSS 8.1 · Published 2026-06-17

Vendors: ThemeREX.

Executive brief

The Ingenioso theme for WordPress contains a security flaw that allows unauthorized users to access sensitive files on the web server. By exploiting this vulnerability, an attacker could view configuration files containing database credentials or other private information, potentially leading to a full site takeover. This issue affects all versions of the theme up to and including 1.14.0.

Technical details

The Ingenioso theme for WordPress (versions <= 1.14.0) suffers from a Local File Inclusion (LFI) vulnerability due to improper control of filenames in PHP include/require statements (CWE-98). An unauthenticated remote attacker can exploit this by sending crafted requests to the server, forcing the application to include and execute local files. This can lead to the disclosure of sensitive information, such as the wp-config.php file, or potentially remote code execution if the attacker can upload or influence the content of a local file. As of the advisory date, no official patch has been released.

Affected products

  • ThemeREX Ingenioso <= 1.14.0

Timeline

  • 2025-10-15: other: Vulnerability reported by researcher
  • 2026-05-26: advisory: Patchstack published advisory details
  • 2026-06-17: disclosed: CVE published in NVD

References