PatchSiren

ThemeRex CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL ThemeRex CVE published 2026-09-11

CVE-2026-62105

Unauthenticated PHP Object Injection vulnerability in ThemeREX Addons versions less than 2.45.0 allows for potential code execution. Defenders should verify exposure and apply patches due to the critical severity rating of 9.8. The CVE record and NVD entry provide limited information, and further review is necessary to understand the full impact. Confirm affected product deployments exist in managed envir [truncated]

CRITICAL ThemeREX CVE published 2026-08-06

CVE-2026-65573

CVE-2026-65573 is a critical unauthenticated PHP object injection vulnerability in Abelle theme version 1.22 or earlier. The vulnerability has a CVSS score of 9.8 and is considered critical. Affected users should review official advisories, verify affected scope, and apply vendor patches or updates. The CVE record was published on 2026-08-06T15:17:18.813Z and has not been modified since then. Defenders sh [truncated]

HIGH ThemeREX CVE published 2026-06-17

CVE-2025-69175

CVE-2025-69175 is a HIGH severity vulnerability (CVSS Score: 8.1) in the Line Agency theme, version <= 1.3.1. This vulnerability allows unauthenticated local file inclusion. The CVE was published on 2026-06-17T14:17:35.790Z and last modified on 2026-06-17T15:16:39.937Z. Users of the affected theme should take immediate action to mitigate potential risks.

HIGH ThemeREX CVE published 2026-06-17

CVE-2025-69174

CVE-2025-69174 is a HIGH severity vulnerability with a CVSS score of 8.1, affecting Etude theme versions <= 1.6. It allows unauthenticated local file inclusion, potentially leading to file inclusion attacks. Users of Etude theme version <= 1.6 should prioritize patching this vulnerability to prevent potential security breaches. The vulnerability has been identified in the Etude theme, and its exploitation [truncated]

HIGH ThemeREX CVE published 2026-06-17

CVE-2025-69166

CVE-2025-69166 is a HIGH severity vulnerability with a CVSS score of 8.1, affecting Gunslinger theme versions up to and including 1.7. It allows unauthenticated local file inclusion. The vulnerability has a CVSS vector of CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H. Users of Gunslinger theme version 1.7 or earlier should be aware of this vulnerability and take necessary actions to protect their installat [truncated]

HIGH ThemeREX CVE published 2026-06-17

CVE-2025-69164

CVE-2025-69164 is a HIGH severity vulnerability (CVSS Score: 8.1) affecting Skyward theme versions <= 1.10. This vulnerability allows unauthenticated local file inclusion. The CVE was published on 2026-06-17T14:17:34.923Z and last modified on 2026-06-17T15:16:39.180Z. Organizations using affected Skyward theme versions should take immediate action to mitigate potential risks.

HIGH ThemeREX CVE published 2026-06-17

CVE-2025-69158

CVE-2025-69158 is a HIGH severity vulnerability (CVSS Score: 8.1) in the Granola theme, affecting versions up to 1.13. This vulnerability allows unauthenticated local file inclusion, potentially enabling attackers to access sensitive files. The vulnerability was published on June 17, 2026, and last modified on the same day. Organizations using the affected Granola theme versions should take immediate acti [truncated]

HIGH ThemeREX CVE published 2026-06-17

CVE-2025-69157

CVE-2025-69157 is an Unauthenticated Local File Inclusion vulnerability affecting Gamic theme versions <= 1.15. The CVSS score is 8.1, indicating high severity. According to the CVE record, the vulnerability was published on 2026-06-17T14:17:34.617Z and last modified on 2026-06-17T15:16:38.860Z. This type of vulnerability allows attackers to include files on a server through a web browser, potentially lea [truncated]

HIGH ThemeREX CVE published 2026-06-17

CVE-2025-69144

CVE-2025-69144 is a HIGH severity vulnerability (CVSS Score: 8.1) in the Preservation theme for WordPress versions <= 1.10. This vulnerability allows unauthenticated local file inclusion, potentially enabling attackers to access sensitive files and data. The vulnerability was published on June 17, 2026, and last modified on the same day. Organizations using the Preservation theme should take immediate act [truncated]

CRITICAL ThemeREX CVE published 2026-06-17

CVE-2025-69127

CVE-2025-69127 is a critical unauthenticated PHP object injection vulnerability in the Plumbing theme, affecting versions <= 1.6. With a CVSS score of 9.8, this vulnerability allows attackers to execute arbitrary code on the server. Evidence from official CVE services indicates ThemeREX as the affected vendor. Limited information is available on the scope of affected systems and potential exploit vectors.

HIGH ThemeREX CVE published 2026-06-17

CVE-2025-69126

CVE-2025-69126 is an Unauthenticated Local File Inclusion vulnerability in Fortius theme versions <= 2.3.0. This vulnerability has a CVSS score of 8.1 and is classified as HIGH severity. The CVE record was published on 2026-06-17T14:17:33.170Z and has not been modified since then. Affected users should assess and mitigate this vulnerability to prevent potential attacks.

HIGH ThemeREX CVE published 2026-06-17

CVE-2025-69123

CVE-2025-69123 is an Unauthenticated Local File Inclusion vulnerability in Snow Club theme version 1.1 or earlier. The vulnerability has a CVSS score of 8.1 and is classified as HIGH severity. Users of Snow Club theme version 1.1 or earlier should prioritize patching to prevent potential local file inclusion attacks. The CVE record was published on 2026-06-17T14:17:32.927Z and has not been modified since [truncated]

HIGH ThemeREX CVE published 2026-06-17

CVE-2025-69120

CVE-2025-69120 is a high-severity unauthenticated local file inclusion vulnerability in the Dazzle theme for WordPress, affecting version 1.0.0 or earlier. The vulnerability has a CVSS score of 8.1 and is classified as HIGH severity. The Common Vulnerability Scoring System (CVSS) vector is CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H. Users of the Dazzle theme for WordPress should apply patches or mitigat [truncated]

HIGH ThemeREX CVE published 2026-06-17

CVE-2025-69115

CVE-2025-69115 is a HIGH-severity vulnerability (CVSS Score: 8.1) affecting the LuxMed | Medicine &amp; Healthcare Doctor WordPress Theme versions 1.2.2 and below. This vulnerability allows unauthenticated local file inclusion attacks. The vulnerability was published on June 17, 2026, and last modified on the same day. Users of the affected theme should take immediate action to mitigate potential risks.

CRITICAL ThemeREX CVE published 2026-06-17

CVE-2025-69111

CVE-2025-69111 is a critical vulnerability in the Reisen theme, allowing unauthenticated PHP object injection. It has a CVSS score of 9.8 and was published on June 17, 2026. The vulnerability affects Reisen theme versions up to 1.4.1. Successful exploitation could lead to severe impacts, including high confidentiality, integrity, and availability risks. Users of the Reisen theme should take immediate acti [truncated]

HIGH ThemeREX CVE published 2026-06-17

CVE-2025-69106

CVE-2025-69106 is an Unauthenticated Local File Inclusion vulnerability in Imba theme versions <= 1.5.0. The CVE record was published on 2026-06-17T14:17:31.797Z and has not been modified since then. This vulnerability has a CVSS score of 8.1 and is considered HIGH severity. Users of Imba theme versions <= 1.5.0 should be aware of this vulnerability and review the supplied official advisory or CVE record [truncated]

HIGH ThemeREX CVE published 2026-06-17

CVE-2026-22338

CVE-2026-22338 is an unauthenticated local file inclusion vulnerability in EcoBlue theme versions <= 1.15. The vulnerability has a CVSS score of 8.1 and is classified as HIGH severity. This type of vulnerability allows attackers to include local files on the server, potentially leading to sensitive information disclosure or code execution. Users of EcoBlue theme versions <= 1.15 should be aware of this vu [truncated]

HIGH ThemeREX CVE published 2026-06-17

CVE-2026-22331

CVE-2026-22331 is a high-severity vulnerability in the AutoParts theme, allowing unauthenticated local file inclusion. This vulnerability has a CVSS score of 8.1 and was published on 2026-06-17. The affected version is 1.5.8 or earlier. Users of the AutoParts theme should take immediate action to mitigate this vulnerability. The vulnerability allows attackers to include local files without authentication, [truncated]

HIGH ThemeREX CVE published 2026-06-17

CVE-2025-69176

CVE-2025-69176 is a HIGH-severity Unauthenticated Local File Inclusion vulnerability in the ITactics theme, version <= 1.0, with a CVSS score of 8.1. This vulnerability allows attackers to include local files without authentication, potentially leading to sensitive information disclosure or code execution. Users of ITactics theme version <= 1.0 should prioritize patching this vulnerability to prevent pote [truncated]

HIGH ThemeREX CVE published 2026-06-17

CVE-2025-69173

CVE-2025-69173 is a HIGH severity vulnerability (CVSS Score: 8.1) affecting the Tipsy theme, version 1.1 or earlier. This vulnerability allows unauthenticated local file inclusion, potentially enabling attackers to access sensitive files. The vulnerability was published on June 17, 2026, and last modified on the same day. The vendor and product information is not confirmed, with a low confidence level. Us [truncated]

HIGH ThemeREX CVE published 2026-06-17

CVE-2025-69172

CVE-2025-69172 is a HIGH-severity vulnerability (CVSS Score: 8.1) affecting the Resurs theme, version <= 1.3. This Unauthenticated Local File Inclusion vulnerability allows attackers to include local files without authentication. The vulnerability was published on June 17, 2026, and last modified on the same day. Users of the affected theme should take immediate action to mitigate potential risks. The ven [truncated]

HIGH ThemeREX CVE published 2026-06-17

CVE-2025-69171

CVE-2025-69171 is a HIGH severity vulnerability (CVSS Score: 8.1) affecting Orpheus theme versions <= 1.3. This vulnerability allows unauthenticated local file inclusion. The CVE was published on 2026-06-17T13:19:24.610Z and last modified on 2026-06-17T14:44:26.397Z. Organizations using the affected Orpheus theme should take immediate action to mitigate this vulnerability.

HIGH ThemeREX CVE published 2026-06-17

CVE-2025-69168

CVE-2025-69168 is an Unauthenticated Local File Inclusion vulnerability in the Spike theme, affecting versions <= 1.2. The vulnerability has a CVSS score of 8.1, indicating high severity. Published on 2026-06-17, this vulnerability allows attackers to include local files without authentication, potentially leading to code execution or information disclosure. Users of the Spike theme version 1.2 or earlier [truncated]

HIGH ThemeREX CVE published 2026-06-17

CVE-2025-69167

CVE-2025-69167 is an Unauthenticated Local File Inclusion vulnerability in the Eros theme, version <= 1.3. This type of vulnerability allows an attacker to include files on a server through a web browser, potentially leading to code execution. The CVSS score for this vulnerability is 8.1, indicating a high severity. The CVE record was published on 2026-06-17T13:19:24.337Z and was last modified on 2026-06- [truncated]

HIGH ThemeREX CVE published 2026-06-17

CVE-2025-69165

CVE-2025-69165 is a HIGH severity vulnerability (CVSS Score: 8.1) in the Choreo theme, affecting versions <= 1.6. This vulnerability allows unauthenticated local file inclusion, potentially leading to data breaches and system compromise. The vulnerability was published on June 17, 2026, and last modified on the same day. Users of the affected theme should take immediate action to mitigate the risk. The ve [truncated]

HIGH ThemeREX CVE published 2026-06-17

CVE-2025-69163

CVE-2025-69163 is an unauthenticated local file inclusion vulnerability in WineShop theme versions <= 3.17. The vulnerability has a CVSS score of 8.1 and is classified as HIGH severity. The CVE record was published on 2026-06-17T13:19:24.013Z and was last modified on 2026-06-17T14:44:26.397Z. This vulnerability affects users of the WineShop theme and requires immediate attention to prevent exploitation.

HIGH ThemeREX CVE published 2026-06-17

CVE-2025-69162

CVE-2025-69162 is a HIGH severity vulnerability (CVSS Score: 8.1) in the Grecko theme, affecting versions up to and including 5.17. This vulnerability allows unauthenticated attackers to include local files, potentially leading to sensitive information disclosure, code execution, or other malicious activities. The vulnerability was published on June 17, 2026, and immediately gained attention due to its hi [truncated]

HIGH ThemeREX CVE published 2026-06-17

CVE-2025-69161

CVE-2025-69161 is a high-severity vulnerability in the Snowy theme, versions <= 1.13, allowing unauthenticated local file inclusion. This vulnerability has a CVSS score of 8.1 and is considered HIGH severity. The vulnerability was published on June 17, 2026, and last modified on the same day. The vendor and product information is not confirmed, with the canonical source being a weak reference domain. Ther [truncated]

HIGH ThemeREX CVE published 2026-06-17

CVE-2025-69159

CVE-2025-69159 is a HIGH severity vulnerability with a CVSS score of 8.1. It is an Unauthenticated Local File Inclusion issue in Printo theme versions <= 1.11. This vulnerability allows attackers to include local files without authentication, potentially leading to code execution or information disclosure. Users of Printo theme version <= 1.11 should apply patches or mitigations to prevent potential file [truncated]

HIGH ThemeREX CVE published 2026-06-17

CVE-2025-69150

CVE-2025-69150 is a HIGH severity vulnerability (CVSS Score: 8.1) in the Medeus theme, affecting versions <= 1.14. This vulnerability allows unauthenticated local file inclusion, potentially enabling attackers to access sensitive files. The vulnerability was published on June 17, 2026, and last modified on the same day. Users of the Medeus theme should take immediate action to mitigate this vulnerability. [truncated]