Junglewise Threat Intelligence

CVE-2025-69166: ThemeREX Gunslinger Local File Inclusion

CVE-2025-69166 · Severity: high · CVSS 8.1 · Published 2026-06-17

Vendors: ThemeREX.

Executive brief

The Gunslinger theme for WordPress is vulnerable to a security flaw that allows unauthorized individuals to access sensitive files on the web server. By exploiting this vulnerability, an attacker could view configuration files containing database credentials, potentially leading to a full site takeover or data breach. There is currently no official patch available from the developer.

Technical details

A Local File Inclusion (LFI) vulnerability exists in the ThemeREX Gunslinger theme for WordPress through version 1.7. The flaw stems from improper control of filenames in PHP include/require statements (CWE-98), allowing an unauthenticated remote attacker to include arbitrary local files via specially crafted requests. While the attack complexity is rated as high, successful exploitation can lead to the disclosure of sensitive information such as wp-config.php or other system files, potentially facilitating remote code execution or database compromise. As of the advisory date, no official patch has been released.

Affected products

  • ThemeREX Gunslinger <= 1.7

Timeline

  • 2025-11-09: other: Vulnerability reported by researcher Bonds
  • 2026-05-27: advisory: Initial disclosure by Patchstack
  • 2026-06-17: disclosed: CVE published and added to NVD

References