Junglewise Threat Intelligence

CVE-2025-69163: ThemeREX WineShop Local File Inclusion

CVE-2025-69163 · Severity: high · CVSS 8.1 · Published 2026-06-17

Vendors: ThemeREX.

Executive brief

WineShop, a WordPress theme used for e-commerce websites, contains a security flaw that allows unauthorized individuals to access sensitive internal files. An attacker could use this to steal database credentials or other configuration data, potentially leading to a full takeover of the website. As of the latest report, there is no official patch available from the developer.

Technical details

A Local File Inclusion (LFI) vulnerability exists in the ThemeREX WineShop theme for WordPress (versions 3.17 and below) due to improper control of filenames in PHP include/require statements (CWE-98). An unauthenticated remote attacker can exploit this by sending crafted requests to include local files from the server. Successful exploitation can lead to the disclosure of sensitive information, such as the wp-config.php file containing database credentials, which may facilitate further attacks or full site compromise. No official patch has been released by the vendor; users are advised to use third-party mitigation rules or switch themes.

Affected products

  • ThemeREX WineShop <= 3.17

Timeline

  • 2025-11-09: other: Vulnerability reported by researcher Bonds
  • 2026-05-27: disclosed: Vulnerability details published by Patchstack
  • 2026-06-17: advisory: CVE published in NVD

References