/Vulnerability Library

WordPress The Wound Theme <= 0.0.1 - Local File Inclusion

CVE-2025-2558
Verified

Description

The-wound WordPress theme through 0.0.1 contains a local file inclusion caused by insufficient validation of parameters used to generate paths passed to include functions, letting unauthenticated users perform LFI attacks and download arbitrary files from the server.

Severity

High

CVSS Score

8.6

Affected Product

the-wound

Published Date

April 9, 2026

Template Author

pussycat0x

CVE-2025-2558.yaml
8.6Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
CWE ID:
cwe-98

References

https://wpscan.com/vulnerability/6a8e1c89-a01d-4347-91fc-ba454784b153/https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-themes/the-wound/the-wound-001-unauthenticated-local-file-inclusionhttps://nvd.nist.gov/vuln/detail/cve-2025-2558

Remediation Steps

Update to the latest version of the theme where the issue is fixed or apply security patches that validate parameters properly.