Unauthenticated Local File Inclusion in Top Dog Theme by WordPress
CVE-2025-69149

8.1HIGH

Key Information:

Vendor

WordPress

Status
Vendor
CVE Published:
16 June 2026

What is CVE-2025-69149?

The Top Dog Theme for WordPress contains an unauthenticated Local File Inclusion vulnerability in versions 1.0.5 and earlier. This flaw allows an attacker to include arbitrary files from the server, which can lead to information disclosure and further compromise of the WordPress site. It is essential for users of affected versions to implement appropriate security measures and update to secure versions to mitigate potential risks associated with this vulnerability.

Affected Version(s)

Top Dog <= 1.0.5

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Bonds | Patchstack Bug Bounty Program
.