Executive brief
The Gamic theme for WordPress is vulnerable to a security flaw that allows unauthorized individuals to access sensitive files on the web server. By exploiting this vulnerability, an attacker could view configuration files containing database credentials or other private information, potentially leading to a full site takeover. This issue affects all versions of the theme up to and including 1.15.
Technical details
A Local File Inclusion (LFI) vulnerability exists in the ThemeREX Gamic theme for WordPress (versions <= 1.15) due to improper control of filenames in PHP include/require statements (CWE-98). An unauthenticated remote attacker can exploit this by sending specially crafted requests to include local files from the server. Successful exploitation can lead to the disclosure of sensitive information, such as the wp-config.php file, which contains database credentials. While the attack complexity is rated as high, no official patch was available at the time of disclosure, and users are advised to use third-party mitigation rules or monitor for theme updates.
Affected products
- ThemeREX Gamic <= 1.15
Timeline
- 2025-11-09: other: Vulnerability reported by researcher Bonds
- 2026-05-27: advisory: Initial advisory published by Patchstack
- 2026-06-17: disclosed: CVE published to NVD