Junglewise Threat Intelligence

CVE-2025-69148: ThemeREX Quirky Local File Inclusion

CVE-2025-69148 · Severity: high · CVSS 8.1 · Published 2026-06-17

Vendors: ThemeREX.

Executive brief

The Quirky theme for WordPress is vulnerable to a security flaw that allows unauthorized individuals to access sensitive files on the web server. By exploiting this vulnerability, an attacker could view configuration files containing database credentials, potentially leading to a full site takeover or data breach. This issue affects all versions of the theme up to and including 1.23, and no official patch has been released yet.

Technical details

A Local File Inclusion (LFI) vulnerability exists in the ThemeREX Quirky theme for WordPress through version 1.23. The flaw stems from improper control of filenames used in PHP include or require statements (CWE-98), allowing an unauthenticated attacker to supply malicious input that references local files on the server. While the attack complexity is rated as high, a successful exploit enables the attacker to disclose sensitive information, such as wp-config.php, which contains database credentials. As of the advisory date, no official patch is available from the developer, though third-party mitigation rules have been proposed.

Affected products

  • ThemeREX (ThemeRex) Quirky <= 1.23

Timeline

  • 2025-10-31: other: Vulnerability reported by researcher Bonds
  • 2026-05-26: disclosed: Vulnerability details published by Patchstack
  • 2026-06-17: advisory: CVE published in NVD

References