Junglewise Threat Intelligence

CVE-2025-69132: Zozothemes Corpkit sensitive data exposure in WordPress theme

CVE-2025-69132 · Severity: medium · CVSS 6.5 · Published 2026-07-02

Executive brief

The Corpkit theme for WordPress is vulnerable to a security flaw that exposes sensitive information to users with basic 'Subscriber' accounts. This could allow an attacker to view data that should normally be restricted, potentially leading to further compromises of the website or its users. As of the latest report, no official patch has been released by the developer.

Technical details

A sensitive data exposure vulnerability (CWE-201) exists in the Zozothemes Corpkit theme for WordPress through version 1.0.5. The flaw allows an authenticated attacker with low-level 'Subscriber' privileges to access sensitive information that is not intended for public or low-privileged viewing. The vulnerability is reachable over the network without user interaction. As of the advisory publication, no official patch is available, though third-party mitigation rules have been suggested. The CVSS 3.1 base score is 6.5, reflecting high confidentiality impact but no impact on integrity or availability.

Affected products

  • Zozothemes Corpkit <= 1.0.5

Timeline

  • 2025-10-19: other: Vulnerability reported by researcher Bonds
  • 2026-06-30: advisory: Patchstack advisory published
  • 2026-07-02: disclosed: CVE published to NVD dataset

References