PatchSiren

ThemeREX CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH ThemeREX CVE published 2026-06-17

CVE-2025-69175

CVE-2025-69175 is a HIGH severity vulnerability (CVSS Score: 8.1) in the Line Agency theme, version <= 1.3.1. This vulnerability allows unauthenticated local file inclusion. The CVE was published on 2026-06-17T14:17:35.790Z and last modified on 2026-06-17T15:16:39.937Z. Users of the affected theme should take immediate action to mitigate potential risks.

HIGH ThemeREX CVE published 2026-06-17

CVE-2025-69174

CVE-2025-69174 is a HIGH severity vulnerability with a CVSS score of 8.1, affecting Etude theme versions <= 1.6. It allows unauthenticated local file inclusion, potentially leading to file inclusion attacks. Users of Etude theme version <= 1.6 should prioritize patching this vulnerability to prevent potential security breaches. The vulnerability has been identified in the Etude theme, and its exploitation [truncated]

HIGH ThemeREX CVE published 2026-06-17

CVE-2025-69166

CVE-2025-69166 is a HIGH severity vulnerability with a CVSS score of 8.1, affecting Gunslinger theme versions up to and including 1.7. It allows unauthenticated local file inclusion. The vulnerability has a CVSS vector of CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H. Users of Gunslinger theme version 1.7 or earlier should be aware of this vulnerability and take necessary actions to protect their installat [truncated]

HIGH ThemeREX CVE published 2026-06-17

CVE-2025-69164

CVE-2025-69164 is a HIGH severity vulnerability (CVSS Score: 8.1) affecting Skyward theme versions <= 1.10. This vulnerability allows unauthenticated local file inclusion. The CVE was published on 2026-06-17T14:17:34.923Z and last modified on 2026-06-17T15:16:39.180Z. Organizations using affected Skyward theme versions should take immediate action to mitigate potential risks.

HIGH ThemeREX CVE published 2026-06-17

CVE-2025-69158

CVE-2025-69158 is a HIGH severity vulnerability (CVSS Score: 8.1) in the Granola theme, affecting versions up to 1.13. This vulnerability allows unauthenticated local file inclusion, potentially enabling attackers to access sensitive files. The vulnerability was published on June 17, 2026, and last modified on the same day. Organizations using the affected Granola theme versions should take immediate acti [truncated]

HIGH ThemeREX CVE published 2026-06-17

CVE-2025-69157

CVE-2025-69157 is an Unauthenticated Local File Inclusion vulnerability affecting Gamic theme versions <= 1.15. The CVSS score is 8.1, indicating high severity. According to the CVE record, the vulnerability was published on 2026-06-17T14:17:34.617Z and last modified on 2026-06-17T15:16:38.860Z. This type of vulnerability allows attackers to include files on a server through a web browser, potentially lea [truncated]

HIGH ThemeREX CVE published 2026-06-17

CVE-2025-69144

CVE-2025-69144 is a HIGH severity vulnerability (CVSS Score: 8.1) in the Preservation theme for WordPress versions <= 1.10. This vulnerability allows unauthenticated local file inclusion, potentially enabling attackers to access sensitive files and data. The vulnerability was published on June 17, 2026, and last modified on the same day. Organizations using the Preservation theme should take immediate act [truncated]

CRITICAL ThemeREX CVE published 2026-06-17

CVE-2025-69127

CVE-2025-69127 is a critical unauthenticated PHP object injection vulnerability in the Plumbing theme, affecting versions <= 1.6. With a CVSS score of 9.8, this vulnerability allows attackers to execute arbitrary code on the server. Evidence from official CVE services indicates ThemeREX as the affected vendor. Limited information is available on the scope of affected systems and potential exploit vectors.

HIGH ThemeREX CVE published 2026-06-17

CVE-2025-69126

CVE-2025-69126 is an Unauthenticated Local File Inclusion vulnerability in Fortius theme versions <= 2.3.0. This vulnerability has a CVSS score of 8.1 and is classified as HIGH severity. The CVE record was published on 2026-06-17T14:17:33.170Z and has not been modified since then. Affected users should assess and mitigate this vulnerability to prevent potential attacks.

HIGH ThemeREX CVE published 2026-06-17

CVE-2025-69123

CVE-2025-69123 is an Unauthenticated Local File Inclusion vulnerability in Snow Club theme version 1.1 or earlier. The vulnerability has a CVSS score of 8.1 and is classified as HIGH severity. Users of Snow Club theme version 1.1 or earlier should prioritize patching to prevent potential local file inclusion attacks. The CVE record was published on 2026-06-17T14:17:32.927Z and has not been modified since [truncated]

HIGH ThemeREX CVE published 2026-06-17

CVE-2025-69120

CVE-2025-69120 is a high-severity unauthenticated local file inclusion vulnerability in the Dazzle theme for WordPress, affecting version 1.0.0 or earlier. The vulnerability has a CVSS score of 8.1 and is classified as HIGH severity. The Common Vulnerability Scoring System (CVSS) vector is CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H. Users of the Dazzle theme for WordPress should apply patches or mitigat [truncated]

HIGH ThemeREX CVE published 2026-06-17

CVE-2025-69115

CVE-2025-69115 is a HIGH-severity vulnerability (CVSS Score: 8.1) affecting the LuxMed | Medicine &amp; Healthcare Doctor WordPress Theme versions 1.2.2 and below. This vulnerability allows unauthenticated local file inclusion attacks. The vulnerability was published on June 17, 2026, and last modified on the same day. Users of the affected theme should take immediate action to mitigate potential risks.

CRITICAL ThemeREX CVE published 2026-06-17

CVE-2025-69111

CVE-2025-69111 is a critical vulnerability in the Reisen theme, allowing unauthenticated PHP object injection. It has a CVSS score of 9.8 and was published on June 17, 2026. The vulnerability affects Reisen theme versions up to 1.4.1. Successful exploitation could lead to severe impacts, including high confidentiality, integrity, and availability risks. Users of the Reisen theme should take immediate acti [truncated]

HIGH ThemeREX CVE published 2026-06-17

CVE-2025-69106

CVE-2025-69106 is an Unauthenticated Local File Inclusion vulnerability in Imba theme versions <= 1.5.0. The CVE record was published on 2026-06-17T14:17:31.797Z and has not been modified since then. This vulnerability has a CVSS score of 8.1 and is considered HIGH severity. Users of Imba theme versions <= 1.5.0 should be aware of this vulnerability and review the supplied official advisory or CVE record [truncated]

HIGH ThemeREX CVE published 2026-06-17

CVE-2026-22338

CVE-2026-22338 is an unauthenticated local file inclusion vulnerability in EcoBlue theme versions <= 1.15. The vulnerability has a CVSS score of 8.1 and is classified as HIGH severity. This type of vulnerability allows attackers to include local files on the server, potentially leading to sensitive information disclosure or code execution. Users of EcoBlue theme versions <= 1.15 should be aware of this vu [truncated]

HIGH ThemeREX CVE published 2026-06-17

CVE-2026-22331

CVE-2026-22331 is a high-severity vulnerability in the AutoParts theme, allowing unauthenticated local file inclusion. This vulnerability has a CVSS score of 8.1 and was published on 2026-06-17. The affected version is 1.5.8 or earlier. Users of the AutoParts theme should take immediate action to mitigate this vulnerability. The vulnerability allows attackers to include local files without authentication, [truncated]

HIGH ThemeREX CVE published 2026-06-17

CVE-2025-69176

CVE-2025-69176 is a HIGH-severity Unauthenticated Local File Inclusion vulnerability in the ITactics theme, version <= 1.0, with a CVSS score of 8.1. This vulnerability allows attackers to include local files without authentication, potentially leading to sensitive information disclosure or code execution. Users of ITactics theme version <= 1.0 should prioritize patching this vulnerability to prevent pote [truncated]

HIGH ThemeREX CVE published 2026-06-17

CVE-2025-69173

CVE-2025-69173 is a HIGH severity vulnerability (CVSS Score: 8.1) affecting the Tipsy theme, version 1.1 or earlier. This vulnerability allows unauthenticated local file inclusion, potentially enabling attackers to access sensitive files. The vulnerability was published on June 17, 2026, and last modified on the same day. The vendor and product information is not confirmed, with a low confidence level. Us [truncated]

HIGH ThemeREX CVE published 2026-06-17

CVE-2025-69172

CVE-2025-69172 is a HIGH-severity vulnerability (CVSS Score: 8.1) affecting the Resurs theme, version <= 1.3. This Unauthenticated Local File Inclusion vulnerability allows attackers to include local files without authentication. The vulnerability was published on June 17, 2026, and last modified on the same day. Users of the affected theme should take immediate action to mitigate potential risks. The ven [truncated]

HIGH ThemeREX CVE published 2026-06-17

CVE-2025-69171

CVE-2025-69171 is a HIGH severity vulnerability (CVSS Score: 8.1) affecting Orpheus theme versions <= 1.3. This vulnerability allows unauthenticated local file inclusion. The CVE was published on 2026-06-17T13:19:24.610Z and last modified on 2026-06-17T14:44:26.397Z. Organizations using the affected Orpheus theme should take immediate action to mitigate this vulnerability.

HIGH ThemeREX CVE published 2026-06-17

CVE-2025-69168

CVE-2025-69168 is an Unauthenticated Local File Inclusion vulnerability in the Spike theme, affecting versions <= 1.2. The vulnerability has a CVSS score of 8.1, indicating high severity. Published on 2026-06-17, this vulnerability allows attackers to include local files without authentication, potentially leading to code execution or information disclosure. Users of the Spike theme version 1.2 or earlier [truncated]

HIGH ThemeREX CVE published 2026-06-17

CVE-2025-69167

CVE-2025-69167 is an Unauthenticated Local File Inclusion vulnerability in the Eros theme, version <= 1.3. This type of vulnerability allows an attacker to include files on a server through a web browser, potentially leading to code execution. The CVSS score for this vulnerability is 8.1, indicating a high severity. The CVE record was published on 2026-06-17T13:19:24.337Z and was last modified on 2026-06- [truncated]

HIGH ThemeREX CVE published 2026-06-17

CVE-2025-69165

CVE-2025-69165 is a HIGH severity vulnerability (CVSS Score: 8.1) in the Choreo theme, affecting versions <= 1.6. This vulnerability allows unauthenticated local file inclusion, potentially leading to data breaches and system compromise. The vulnerability was published on June 17, 2026, and last modified on the same day. Users of the affected theme should take immediate action to mitigate the risk. The ve [truncated]

HIGH ThemeREX CVE published 2026-06-17

CVE-2025-69163

CVE-2025-69163 is an unauthenticated local file inclusion vulnerability in WineShop theme versions <= 3.17. The vulnerability has a CVSS score of 8.1 and is classified as HIGH severity. The CVE record was published on 2026-06-17T13:19:24.013Z and was last modified on 2026-06-17T14:44:26.397Z. This vulnerability affects users of the WineShop theme and requires immediate attention to prevent exploitation.

HIGH ThemeREX CVE published 2026-06-17

CVE-2025-69162

CVE-2025-69162 is a HIGH severity vulnerability (CVSS Score: 8.1) in the Grecko theme, affecting versions up to and including 5.17. This vulnerability allows unauthenticated attackers to include local files, potentially leading to sensitive information disclosure, code execution, or other malicious activities. The vulnerability was published on June 17, 2026, and immediately gained attention due to its hi [truncated]

HIGH ThemeREX CVE published 2026-06-17

CVE-2025-69161

CVE-2025-69161 is a high-severity vulnerability in the Snowy theme, versions <= 1.13, allowing unauthenticated local file inclusion. This vulnerability has a CVSS score of 8.1 and is considered HIGH severity. The vulnerability was published on June 17, 2026, and last modified on the same day. The vendor and product information is not confirmed, with the canonical source being a weak reference domain. Ther [truncated]

HIGH ThemeREX CVE published 2026-06-17

CVE-2025-69159

CVE-2025-69159 is a HIGH severity vulnerability with a CVSS score of 8.1. It is an Unauthenticated Local File Inclusion issue in Printo theme versions <= 1.11. This vulnerability allows attackers to include local files without authentication, potentially leading to code execution or information disclosure. Users of Printo theme version <= 1.11 should apply patches or mitigations to prevent potential file [truncated]

HIGH ThemeREX CVE published 2026-06-17

CVE-2025-69150

CVE-2025-69150 is a HIGH severity vulnerability (CVSS Score: 8.1) in the Medeus theme, affecting versions <= 1.14. This vulnerability allows unauthenticated local file inclusion, potentially enabling attackers to access sensitive files. The vulnerability was published on June 17, 2026, and last modified on the same day. Users of the Medeus theme should take immediate action to mitigate this vulnerability. [truncated]

HIGH ThemeREX CVE published 2026-06-17

CVE-2025-69149

The CVE-2025-69149 vulnerability is an Unauthenticated Local File Inclusion issue in the Top Dog theme versions <= 1.0.5. This vulnerability has a CVSS score of 8.1 and is classified as HIGH severity. The vulnerability allows attackers to include local files without authentication, potentially leading to sensitive information disclosure or code execution. Defenders of systems using Top Dog theme version 1 [truncated]

HIGH ThemeREX CVE published 2026-06-17

CVE-2025-69148

CVE-2025-69148 is a HIGH severity vulnerability (CVSS Score: 8.1) in the Quirky WordPress theme, affecting versions <= 1.23. This vulnerability allows unauthenticated local file inclusion, potentially enabling attackers to access sensitive files on the server. The vulnerability was published on June 17, 2026, and last modified on the same day. Organizations using the affected theme versions should take im [truncated]

HIGH ThemeREX CVE published 2026-06-17

CVE-2025-69146

CVE-2025-69146 is a HIGH severity vulnerability with a CVSS score of 8.1, classified as an Unauthenticated Local File Inclusion issue in the Dom theme versions <= 1.24. This vulnerability allows attackers to include local files without authentication, potentially leading to code execution or information disclosure. Users of the Dom theme should prioritize updating to a patched version to mitigate this vul [truncated]

HIGH ThemeREX CVE published 2026-06-17

CVE-2025-69145

CVE-2025-69145 is a high-severity vulnerability in the Gat theme, affecting versions <= 1.16. This vulnerability allows unauthenticated local file inclusion, with a CVSS score of 8.1. The vulnerability was published on June 17, 2026, and last modified on the same day. Organizations using the affected Gat theme versions should take immediate action to mitigate the risk.

HIGH ThemeREX CVE published 2026-06-17

CVE-2025-69143

The CVE-2025-69143 vulnerability is an Unauthenticated Local File Inclusion issue affecting Mission theme versions <= 1.22. It has a CVSS score of 8.1 and is classified as HIGH severity. This vulnerability could potentially allow attackers to access sensitive files on the server, leading to unauthorized data disclosure or code execution. Users of Mission theme versions <= 1.22 should verify their installa [truncated]

HIGH ThemeREX CVE published 2026-06-17

CVE-2025-69142

CVE-2025-69142 is an Unauthenticated Local File Inclusion vulnerability in Abelle theme versions <= 1.22. The CVSS score is 8.1, indicating a HIGH severity level. This vulnerability allows unauthenticated attackers to include local files, potentially leading to code execution or information disclosure. Users of Abelle theme version <= 1.22 should apply patches or mitigations to prevent potential file incl [truncated]

HIGH ThemeREX CVE published 2026-06-17

CVE-2025-69141

CVE-2025-69141 is a HIGH severity vulnerability (CVSS Score: 8.1) in the Kelly Young theme, affecting versions <= 1.1.0. This vulnerability allows unauthenticated local file inclusion, potentially enabling attackers to access sensitive files. The vulnerability was published on June 17, 2026, and last modified on the same day. Users of the affected theme should take immediate action to mitigate this vulnerability.

HIGH ThemeREX CVE published 2026-06-17

CVE-2025-69125

CVE-2025-69125 is a HIGH severity vulnerability (CVSS Score: 8.1) in the Food Drop theme for WordPress, versions <= 1.3. This vulnerability allows unauthenticated local file inclusion, potentially enabling attackers to access sensitive files. The vulnerability was published on June 17, 2026. Organizations using the affected theme should take immediate action to mitigate potential risks. The CVE record and [truncated]

HIGH ThemeREX CVE published 2026-06-17

CVE-2025-69124

CVE-2025-69124 is a HIGH severity vulnerability with a CVSS score of 8.1, affecting Especio theme versions 1.0 or earlier. It allows unauthenticated local file inclusion, which can lead to potential file inclusion attacks. The vulnerability's CVSS vector is CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H, indicating a high impact on confidentiality, integrity, and availability. Users of Especio theme version [truncated]

CRITICAL ThemeREX CVE published 2026-06-17

CVE-2025-69122

CVE-2025-69122 is a critical vulnerability in the SeaFood Company theme for WordPress, versions <= 1.4, allowing unauthenticated PHP object injection. With a CVSS score of 9.8, this vulnerability poses a significant risk to affected systems. The vulnerability was published on June 17, 2026, and last modified on the same day. Users of the affected theme should take immediate action to mitigate the risk. Th [truncated]

HIGH ThemeREX CVE published 2026-06-17

CVE-2025-69121

CVE-2025-69121 is a HIGH severity vulnerability (CVSS Score: 8.1) in the Deliciosa theme, affecting versions up to 1.10.0. This vulnerability allows unauthenticated local file inclusion, potentially enabling attackers to access sensitive files. The vulnerability was published on June 17, 2026, and last modified on the same day. Users of the Deliciosa theme should take immediate action to mitigate this risk.

HIGH ThemeREX CVE published 2026-06-17

CVE-2025-69119

CVE-2025-69119 is an Unauthenticated Local File Inclusion vulnerability in Corbesier theme versions <= 1.15.0. The CVSS score is 8.1, indicating a HIGH severity level. This vulnerability allows unauthenticated attackers to include local files, potentially leading to code execution or information disclosure. Users of Corbesier theme version 1.15.0 or earlier should prioritize updating to a patched version [truncated]

HIGH ThemeREX CVE published 2026-06-17

CVE-2025-69118

CVE-2025-69118 is a high-severity vulnerability in the CopyPress WordPress theme, with a CVSS score of 8.1. The vulnerability allows unauthenticated attackers to include local files, potentially leading to code execution, data breaches, or other malicious activities. This vulnerability was published on June 17, 2026, and immediately gained attention due to its high severity and potential impact. Users of [truncated]

HIGH ThemeREX CVE published 2026-06-17

CVE-2025-69117

CVE-2025-69117 is an unauthenticated local file inclusion vulnerability in Ingenioso versions <= 1.14.0. The vulnerability has a CVSS score of 8.1 and is classified as HIGH severity. This type of vulnerability could allow an attacker to access sensitive files on the system, potentially leading to unauthorized data disclosure or system compromise. Users of Ingenioso versions <= 1.14.0 should be aware of th [truncated]

HIGH ThemeREX CVE published 2026-06-17

CVE-2025-69116

CVE-2025-69116 is a high-severity vulnerability in the Iona theme, affecting versions <= 1.0.8. This vulnerability allows unauthenticated local file inclusion, with a CVSS score of 8.1. The vulnerability was published on June 17, 2026, and last modified on the same day. The vendor and product information are not confirmed, with a low confidence level. Users of the Iona theme should take immediate action t [truncated]

HIGH ThemeREX CVE published 2026-06-17

CVE-2025-69114

CVE-2025-69114 is an Unauthenticated Local File Inclusion vulnerability affecting MaxiNet versions less than or equal to 1.2.10. The vulnerability has a CVSS score of 8.1 and is classified as HIGH severity. This type of vulnerability could allow an attacker to access sensitive files on the system, potentially leading to unauthorized data disclosure or system compromise. Users of MaxiNet versions less than [truncated]

HIGH ThemeREX CVE published 2026-06-17

CVE-2025-69113

CVE-2025-69113 is a high-severity vulnerability (CVSS Score: 8.1) affecting Nexio versions <= 1.10.0. This vulnerability allows unauthenticated local file inclusion, potentially leading to sensitive information disclosure and system compromise. The vulnerability was published on June 17, 2026, and immediately gained attention due to its high severity and potential impact. Users of affected Nexio versions [truncated]

HIGH ThemeREX CVE published 2026-06-17

CVE-2025-69112

CVE-2025-69112 is a HIGH severity vulnerability (CVSS Score: 8.1) in the Planty theme, affecting versions up to 1.14.0. This vulnerability allows unauthenticated local file inclusion. The CVE was published on 2026-06-17T13:19:17.100Z and last modified on 2026-06-17T14:45:15.717Z. Users of the affected theme should take immediate action to mitigate potential risks.

HIGH ThemeREX CVE published 2026-06-17

CVE-2025-69110

CVE-2025-69110 is an Unauthenticated Local File Inclusion vulnerability in AirSupply theme versions <= 2.0.0. The vulnerability has a CVSS score of 8.1 and is classified as HIGH. The CVSS vector is CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H. The weakness is CWE-98. Users of AirSupply theme versions <= 2.0.0 should be aware of this vulnerability and take necessary actions to protect their systems. The CV [truncated]

HIGH ThemeREX CVE published 2026-06-17

CVE-2025-69109

CVE-2025-69109 is a high-severity unauthenticated local file inclusion vulnerability in Raider Spirit theme versions <= 1.1.2. The vulnerability allows attackers to include local files without authentication, potentially leading to sensitive information disclosure or code execution. Users of Raider Spirit theme version 1.1.2 or earlier should prioritize patching this vulnerability to prevent potential fil [truncated]

CRITICAL ThemeREX CVE published 2026-06-17

CVE-2025-69108

CVE-2025-69108 is a critical vulnerability in the Hot Coffee theme, affecting versions up to 1.7. This vulnerability allows for unauthenticated PHP object injection, posing a significant risk to affected systems. With a CVSS score of 9.8, it is considered highly severe. The vulnerability was published on June 17, 2026, and last modified on the same day. Users of the Hot Coffee theme should take immediate [truncated]

HIGH ThemeREX CVE published 2026-06-17

CVE-2025-69107

CVE-2025-69107 is a high-severity Unauthenticated Local File Inclusion vulnerability in the Rosaleen theme, affecting versions <= 2.8. The vulnerability has a CVSS score of 8.1. This type of vulnerability allows unauthenticated attackers to include local files, potentially leading to code execution or information disclosure. Users of the Rosaleen theme version 2.8 or earlier should prioritize patching thi [truncated]