Junglewise Threat Intelligence

CVE-2025-69177: THEMELOGI Roneous Local File Inclusion

CVE-2025-69177 · Severity: high · CVSS 8.1 · Published 2026-06-17

Executive brief

The Roneous theme for WordPress, used to design and manage website layouts, contains a security flaw that allows unauthorized users to access sensitive internal files. An attacker could use this to steal configuration data, such as database credentials, potentially leading to a full takeover of the website and its data. As of the latest report, no official patch has been released by the developer.

Technical details

A Local File Inclusion (LFI) vulnerability exists in the Roneous WordPress theme due to improper control of filenames in PHP 'include' or 'require' statements (CWE-98). The flaw allows an unauthenticated remote attacker to manipulate input to include local files from the server's filesystem. While the attack complexity is rated as high, a successful exploit could lead to the disclosure of sensitive information like wp-config.php or other system files, potentially resulting in full site compromise. No official patch is currently available for versions 2.1.5 and below.

Affected products

  • THEMELOGI Roneous <= 2.1.5

Timeline

  • 2025-11-10: other: Vulnerability reported by researcher João Pedro S Alcântara (Kinorth)
  • 2026-05-27: disclosed: Vulnerability details published by Patchstack
  • 2026-06-17: advisory: CVE published in the National Vulnerability Database (NVD)

References