CVE-2025-2558 Details
Description
The-wound WordPress theme through 0.0.1 does not validate some parameters before using them to generate paths passed to include function/s, allowing unauthenticated users to perform LFI attacks and download arbitrary file from the server
A local file inclusion (LFI) vulnerability has been identified in the The Wound WordPress theme, versions through 0.0.1. The issue arises because the theme fails to properly validate certain parameters before using them to generate file paths for include functions. This lack of validation allows unauthenticated users to exploit the vulnerability, potentially leading to the download of arbitrary files from the server.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 24, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://wpscan.com/vulnerability/6a8e1c89-a01d-4347-91fc-ba454784b153/ | CISA-ADP | ExploitThird Party Advisory |
| https://wpscan.com/vulnerability/6a8e1c89-a01d-4347-91fc-ba454784b153/ | [email protected] | ExploitThird Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| the wound project the wound | <= 0.0.1 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 23, 2025 | Initial Analysis | [email protected] |
| Apr 24, 2025 | CVE Modified | CISA-ADP |
| Apr 24, 2025 | New CVE Received | [email protected] |