PT-2025-17690 · WordPress · The-Wound

Aly Khaled

·

Published

2025-04-24

·

Updated

2026-04-09

·

CVE-2025-2558

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions The-wound WordPress theme version 0.0.1
Description The issue concerns the failure to validate certain parameters before using them to generate paths passed to include functions, allowing unauthenticated users to perform Local File Inclusion (LFI) attacks and download arbitrary files from the server. This enables attackers to access sensitive information on the server.
Recommendations For The-wound WordPress theme version 0.0.1, consider updating to a newer version that addresses this issue, as the current version does not validate parameters properly, leading to LFI vulnerabilities. If an update is not available, as a temporary workaround, consider restricting access to include functions or validating parameters manually to prevent LFI attacks. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Related Identifiers

CVE-2025-2558

Affected Products

The-Wound