CVE-2025-69402: WordPress R&F theme <= 1.5 - Local File Inclusion vulnerability
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX R&F rf allows PHP Local File Inclusion.This issue affects R&F: from n/a through <= 1.5.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-69402?
CVE-2025-69402 is classified as a critical Local File Inclusion vulnerability affecting the WordPress R&F theme version 1.5 and below.
How do I fix CVE-2025-69402?
To fix CVE-2025-69402, you should update the WordPress R&F theme to the latest version that addresses this vulnerability.
What are the risks associated with CVE-2025-69402?
The risks associated with CVE-2025-69402 include unauthorized access to sensitive files and potential remote code execution.
How can I determine if I am affected by CVE-2025-69402?
You are affected by CVE-2025-69402 if you are using the WordPress R&F theme version 1.5 or earlier.
Can CVE-2025-69402 be exploited remotely?
Yes, CVE-2025-69402 can be exploited remotely if an attacker manipulates file inclusion functionality within the vulnerable theme.