Junglewise Threat Intelligence

CVE-2025-69165: ThemeREX Choreo local file inclusion in WordPress theme

CVE-2025-69165 · Severity: high · CVSS 8.1 · Published 2026-06-17

Vendors: ThemeREX.

Executive brief

The Choreo theme for WordPress is vulnerable to a security flaw that allows unauthorized individuals to access sensitive files on the web server. By exploiting this, an attacker could view configuration files containing database credentials or other private information, potentially leading to a full takeover of the website. As of the latest report, no official patch has been released by the developer.

Technical details

A Local File Inclusion (LFI) vulnerability exists in the Choreo theme for WordPress through version 1.6 due to improper control of filenames in PHP include/require statements (CWE-98). An unauthenticated remote attacker can exploit this by sending specially crafted requests to include local files from the server's filesystem. Successful exploitation can lead to the disclosure of sensitive information, such as wp-config.php, or potentially remote code execution if the attacker can influence the contents of a file being included. The vulnerability has a CVSS score of 8.1, reflecting high impact but noting a high attack complexity. No official patch is currently available.

Affected products

  • ThemeREX Choreo <= 1.6

Timeline

  • 2025-11-09: other: Vulnerability reported by researcher Bonds
  • 2026-05-27: advisory: Patchstack published advisory details
  • 2026-06-17: disclosed: CVE published to NVD

References