WordPress The Wound Theme <= 0.0.1 - Local File Inclusion
CVE-2025-2558
Verified
Description
The-wound WordPress theme through 0.0.1 contains a local file inclusion caused by insufficient validation of parameters used to generate paths passed to include functions, letting unauthenticated users perform LFI attacks and download arbitrary files from the server.
Severity
High
CVSS Score
8.6
Affected Product
the-wound
Published Date
April 9, 2026
Template Author
pussycat0x
CVE-2025-2558.yaml
8.6Score
CVSS Metrics
CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
CWE ID:
cwe-98
Remediation Steps
Update to the latest version of the theme where the issue is fixed or apply security patches that validate parameters properly.