Junglewise Threat Intelligence

CVE-2025-69138: Jthemes Genemy privilege escalation in WordPress theme

CVE-2025-69138 · Severity: high · CVSS 8.8 · Published 2026-06-17

Executive brief

The Genemy theme for WordPress is vulnerable to a security flaw that allows users with low-level 'Subscriber' accounts to gain administrative control over the website. An attacker could use this access to modify site content, steal user data, or completely lock out the legitimate owners. As of the latest report, no official patch has been released by the developer.

Technical details

A privilege escalation vulnerability exists in the Jthemes Genemy theme for WordPress through version 1.6.6. The flaw is classified as CWE-266 (Incorrect Privilege Assignment), which allows an authenticated user with 'Subscriber' privileges to escalate their permissions, potentially to the 'Administrator' level. The attack is reachable over the network and requires no user interaction. While the vulnerability has been disclosed, no official patch is currently available from the vendor, though third-party mitigation rules have been issued by security providers.

Affected products

  • Jthemes Genemy <= 1.6.6

Timeline

  • 2025-10-28: other: Vulnerability reported by researcher
  • 2026-05-26: advisory: Patchstack advisory published
  • 2026-06-17: disclosed: CVE published to NVD

References

Related threats