Junglewise Threat Intelligence

CVE-2025-69170: ThemeREX Eventicity Local File Inclusion

CVE-2025-69170 · Severity: high · CVSS 8.1 · Published 2026-06-17

Vendors: ThemeREX.

Executive brief

Eventicity, a WordPress theme used for event management websites, contains a security flaw that allows unauthorized individuals to access sensitive internal files. By exploiting this vulnerability, an attacker could view configuration files containing database credentials or other private data, potentially leading to a full takeover of the website. There is currently no official patch available from the developer.

Technical details

The Eventicity theme for WordPress (versions <= 1.5) is vulnerable to Local File Inclusion (LFI) due to improper control of filenames passed to PHP include/require statements (CWE-98). An unauthenticated remote attacker can exploit this by sending specially crafted requests to include local files from the server's filesystem. Successful exploitation can lead to the disclosure of sensitive information, such as the wp-config.php file containing database credentials, or potentially remote code execution if the attacker can upload or influence the content of a local file. As of the advisory date, no official patch has been released, and users are advised to use third-party security rules or migrate to a supported theme.

Affected products

  • ThemeREX Eventicity <= 1.5

Timeline

  • 2025-11-09: other: Vulnerability reported by researcher Bonds
  • 2026-05-27: advisory: Patchstack published advisory details
  • 2026-06-17: disclosed: CVE published to NVD

References