Junglewise Threat Intelligence

CVE-2025-69178: CactusThemes Truemag Local File Inclusion

CVE-2025-69178 · Severity: high · CVSS 8.1 · Published 2026-06-17

Executive brief

Truemag, a WordPress theme used for building magazine and portfolio websites, contains a security flaw that allows unauthorized users to access sensitive internal files. An attacker could use this to steal configuration data, such as database credentials, potentially leading to a full takeover of the website. There is currently no official patch available from the developer.

Technical details

A Local File Inclusion (LFI) vulnerability exists in the CactusThemes Truemag theme for WordPress through version 4.3.14.2. The flaw stems from improper control of filenames in PHP include/require statements (CWE-98), allowing an unauthenticated remote attacker to specify local files for execution or disclosure. While the attack complexity is rated as high, successful exploitation can lead to the exposure of sensitive files like wp-config.php, which contains database credentials. As of the advisory date, no official patch has been released, and users are advised to use third-party mitigation rules or switch themes.

Affected products

  • CactusThemes Truemag <= 4.3.14.2

Timeline

  • 2025-11-11: other: Vulnerability reported by researcher João Pedro S Alcântara
  • 2026-05-27: advisory: Patchstack published advisory details
  • 2026-06-17: disclosed: CVE published to NVD

References