Junglewise Threat Intelligence

CVE-2025-69159: ThemeREX Printo Local File Inclusion

CVE-2025-69159 · Severity: high · CVSS 8.1 · Published 2026-06-17

Vendors: ThemeREX.

Executive brief

The Printo theme for WordPress is vulnerable to a security flaw that allows unauthorized individuals to access sensitive files on the web server. By exploiting this vulnerability, an attacker could view configuration files containing database credentials, potentially leading to a full site takeover or data breach. This issue affects all versions of the theme up to and including 1.11, and there is currently no official patch available.

Technical details

A Local File Inclusion (LFI) vulnerability exists in the Printo theme for WordPress due to improper control of filenames in PHP 'include' or 'require' statements (CWE-98). An unauthenticated remote attacker can exploit this by sending specially crafted requests to include local files from the server. Successful exploitation can result in the disclosure of sensitive information, such as the wp-config.php file, which contains database credentials. While the attack vector is network-based and requires no privileges, the CVSS assessment indicates high complexity, likely due to specific environmental or configuration requirements needed to trigger the inclusion. As of the advisory date, no official patch has been released by the vendor.

Affected products

  • ThemeREX Printo <= 1.11

Timeline

  • 2025-11-09: other: Vulnerability reported by researcher Bonds
  • 2026-05-27: advisory: Patchstack published advisory details
  • 2026-06-17: disclosed: CVE published to NVD

References