
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-69402 is a PHP Local File Inclusion (LFI) vulnerability in the ThemeREX R&F WordPress theme, classified under CWE-98 (Improper Control of Filename for Include/Require Statement in PHP Program). It affects all versions of the R&F theme through version 1.5 and allows unauthenticated, network-based attackers to include and execute arbitrary local files on the server. The vulnerability was published on February 20, 2026, and carries a CVSS v3.1 base score of 8.1 (High) (Feedly).
The root cause is improper control of filenames passed to PHP include/require statements within the ThemeREX R&F theme (CWE-98), which fails to adequately validate or sanitize user-supplied input before using it in file inclusion operations. An unauthenticated remote attacker can craft a malicious HTTP request supplying a controlled filename parameter that causes the PHP interpreter to include arbitrary local files from the server's filesystem. Exploitation requires high attack complexity (AC:H per CVSS), suggesting some precondition such as knowledge of file paths or specific server configuration, but no authentication or user interaction is needed (Feedly, Wordfence).
Successful exploitation can result in high-severity impacts across confidentiality, integrity, and availability. An attacker could read sensitive local files (e.g., WordPress wp-config.php containing database credentials), execute arbitrary PHP code by including log files or other attacker-controlled content, modify application behavior, or fully compromise the underlying web server. The scope is limited to the affected system, but credential exposure could enable lateral movement to connected databases or services (Feedly).
As of the time of reporting, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (Feedly). The EPSS score is approximately 0.053%, indicating a low current probability of exploitation in the near term. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported.
style.css files.include/require statements without sanitization.../../../../wp-config.php or /etc/passwd) using path traversal sequences.wp-config.php) to access the database, create admin accounts, or pivot to other systems (Feedly).../, ..%2F, %2e%2e%2f) in query parameters; requests returning unexpected file content (e.g., PHP config files).bash, curl, wget) that may indicate successful code execution following LFI-to-RCE escalation (Feedly).No official patch has been released for the ThemeREX R&F theme as of the time of reporting (Feedly). Administrators should immediately audit all WordPress installations for use of the R&F theme version 1.5 or earlier and consider disabling or replacing the theme until a fix is available. As interim mitigations: implement Web Application Firewall (WAF) rules to block path traversal and file inclusion patterns; apply strict server-side input validation and whitelist-based file inclusion controls; restrict PHP's open_basedir setting to limit accessible directories; and monitor application logs for suspicious file inclusion attempts. Contact ThemeREX directly for patch availability and upgrade as soon as a fixed version is released.
The vulnerability was noted in Wordfence's weekly WordPress vulnerability report for the period of February 9–15, 2026, indicating it was tracked by the WordPress security community shortly after disclosure (Wordfence). No significant vendor statements, researcher commentary, or broader media coverage has been identified beyond standard vulnerability database listings.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."