
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-69049 is a Local File Inclusion (LFI) vulnerability in the Elated-Themes Töbel WordPress theme, classified under CWE-98 (Improper Control of Filename for Include/Require Statement in PHP Program). It affects all versions of the Töbel theme up to and including version 1.6. The vulnerability was reported on June 10, 2025, and published to NVD on January 22, 2026. It carries a CVSS v3.1 base score of 8.1 (High) (Patchstack, Feedly).
The root cause is improper control of filename parameters used in PHP include/require statements within the Töbel WordPress theme (CWE-98). An unauthenticated remote attacker can manipulate file path parameters passed to these PHP inclusion functions to load arbitrary local files from the server's filesystem. No authentication or user interaction is required, though the attack complexity is rated High, suggesting some precondition or bypass technique is needed. No public proof-of-concept or detailed technical write-up has been published at this time (Patchstack, Feedly).
Successful exploitation allows an unauthenticated attacker to read arbitrary files on the web server, including sensitive configuration files such as wp-config.php (which contains database credentials), potentially enabling full database takeover. The vulnerability carries high impacts to confidentiality, integrity, and availability. Depending on server configuration, LFI may also be chained with log poisoning or other techniques to achieve remote code execution (Patchstack, Feedly).
No public proof-of-concept exploit code has been published, and there is no evidence of active in-the-wild exploitation at this time. The EPSS score is approximately 0.053%, indicating a low current probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Patchstack notes that vulnerabilities of this class and severity are commonly used in mass-exploit campaigns targeting WordPress sites regardless of traffic size (Patchstack, Feedly).
No official patch from the theme developer (Elated-Themes) is currently available for Töbel version 1.6 or earlier. Site owners should immediately inventory all WordPress installations using the Töbel theme and consider replacing or disabling it until a patch is released. Patchstack has issued a virtual patching/mitigation rule to block exploitation attempts for subscribers of their service. Additional interim measures include implementing Web Application Firewall (WAF) rules to block file inclusion attack patterns, restricting PHP file system access permissions, and enforcing strict input validation on file path parameters (Patchstack, Feedly).
Patchstack, which credited researcher "Bonds" for the discovery, classified this as a high-priority vulnerability and issued a virtual mitigation rule given the absence of an official patch. The vulnerability was also noted in the Wordfence Intelligence weekly WordPress vulnerability report covering the period of December 15, 2025 to January 4, 2026 (Wordfence, Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."