Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Kyle Bouchard

#24235of 53,634
9.8Total CVSS
Vulnerabilities · 1
PT-2025-22325
9.8
2025-05-21
WordPress · Madara · CVE-2025-4524
**Name of the Vulnerable Software and Affected Versions** Madara – Responsive and modern WordPress theme for manga sites versions 2.2.2 and earlier **Description** The issue allows unauthenticated attackers to include and execute arbitrary files on the server via the `template` parameter, making it possible to bypass access controls, obtain sensitive data, or achieve code execution. This can be particularly problematic in cases where images and other “safe” file types can be uploaded and included. **Recommendations** For Madara – Responsive and modern WordPress theme for manga sites versions 2.2.2 and earlier, consider disabling the `template` parameter until a patch is available to prevent exploitation. Restrict access to sensitive files and directories to minimize the risk of arbitrary file inclusion. Avoid using the `template` parameter in API endpoints until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.