Executive brief
The Spike theme for WordPress is vulnerable to a security flaw that allows unauthorized users to access sensitive files on the web server. By exploiting this vulnerability, an attacker could view configuration files containing database credentials, potentially leading to a full takeover of the website and its data. This is particularly serious as it can be performed without any login credentials, though no official fix has been released yet.
Technical details
A Local File Inclusion (LFI) vulnerability exists in the ThemeREX Spike theme for WordPress through version 1.2. The flaw stems from improper control of filenames used in PHP include or require statements (CWE-98), allowing an unauthenticated remote attacker to include arbitrary files from the local file system. While the attack complexity is rated as high, a successful exploit could allow the attacker to read sensitive system files (such as wp-config.php) or execute code if they can upload or find a controllable file on the server. As of the advisory date, no official patch is available, and users are encouraged to use third-party mitigation rules.
Affected products
- ThemeREX Spike <= 1.2
Timeline
- 2025-11-09: other: Vulnerability reported by researcher Bonds
- 2026-05-27: disclosed: Vulnerability details published by Patchstack
- 2026-06-17: advisory: CVE published in NVD