VYPR
Unrated severityNVD Advisory· Published Jun 16, 2026

WordPress Learnify theme <= 1.15.0 - Local File Inclusion vulnerability

CVE-2025-60085

Description

Learnify theme <= 1.15.0 for WordPress exposes an unauthenticated local file inclusion (LFI), allowing remote attackers to read sensitive server files.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Learnify theme <= 1.15.0 for WordPress exposes an unauthenticated local file inclusion (LFI), allowing remote attackers to read sensitive server files.

Vulnerability

The Learnify WordPress theme, version 1.15.0 and earlier, contains an unauthenticated local file inclusion (LFI) vulnerability. An attacker does not need any authentication to trigger the vulnerable code path, which allows inclusion of arbitrary local files on the server.

Exploitation

An attacker with network access to the target WordPress site can send crafted HTTP requests to the affected Learnify theme endpoint. No authentication, user interaction, or special privileges are required. The attack can be performed remotely and automated.

Impact

Successful exploitation results in the attacker reading arbitrary local files of the target website, including files containing database credentials and other sensitive configuration data. Depending on the server configuration, this could lead to a full database compromise and further escalation [1].

Mitigation

The official vendor has not released a patched version as of the publication date. Administrators should immediately update the Learnify theme if a fix is made available. If no update exists, the theme should be replaced or disabled, and website access restricted. The vulnerability has been flagged as a potential entry point for mass-exploit campaigns [1].

AI Insight generated on Jun 17, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.

References

1

News mentions

0

No linked articles in our index yet.