CVE-2025-69396: WordPress Splendour theme <= 1.23 - Local File Inclusion vulnerability
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Splendour splendour allows PHP Local File Inclusion.This issue affects Splendour: from n/a through <= 1.23.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-69396?
CVE-2025-69396 has a high severity due to its Local File Inclusion vulnerability, which can lead to unauthorized file access and potential exploitation.
How do I fix CVE-2025-69396?
To fix CVE-2025-69396, update the ThemeREX Splendour theme to version 1.24 or later, which addresses this vulnerability.
What versions of the Splendour theme are affected by CVE-2025-69396?
CVE-2025-69396 affects all versions of the ThemeREX Splendour theme up to and including version 1.23.
What type of vulnerability is CVE-2025-69396?
CVE-2025-69396 is classified as a Local File Inclusion vulnerability, allowing attackers to include files on the server.
Who is the vendor for CVE-2025-69396?
The vendor for CVE-2025-69396 is ThemeREX, which develops the Splendour theme for WordPress.