Junglewise Threat Intelligence

CVE-2025-69171: ThemeREX Orpheus Local File Inclusion in WordPress theme

CVE-2025-69171 · Severity: high · CVSS 8.1 · Published 2026-06-17

Vendors: ThemeREX.

Executive brief

The Orpheus theme for WordPress is vulnerable to a security flaw that allows unauthorized individuals to access sensitive files on the web server. By exploiting this vulnerability, an attacker could view internal configuration files, such as those containing database credentials, potentially leading to a full takeover of the website and its data. As of the latest report, there is no official patch available from the developer.

Technical details

A Local File Inclusion (LFI) vulnerability exists in the ThemeREX Orpheus theme for WordPress through version 1.3. The flaw stems from improper control of filenames used in PHP include or require statements (CWE-98), allowing an unauthenticated remote attacker to specify local files for execution or display. While the attack complexity is rated as high, a successful exploit enables the attacker to read sensitive files like wp-config.php, which contains database credentials, or potentially achieve remote code execution if they can upload or locate controllable file content on the server. No official patch has been released; users are advised to seek alternative themes or use third-party security filtering.

Affected products

  • ThemeREX Orpheus <= 1.3

Timeline

  • 2025-11-09: other: Vulnerability reported by researcher Bonds
  • 2026-05-27: disclosed: Vulnerability details published by Patchstack
  • 2026-06-17: advisory: CVE published in NVD

References