/Vulnerability Library

WordPress Madara Theme < 2.2.2.1 - Local File Inclusion

CVE-2025-4524
Verified

Description

Madara WordPress theme <= 2.2.2 contains a local file inclusion vulnerability caused by improper sanitization of the 'template' parameter, letting unauthenticated attackers execute arbitrary files on the server, exploit requires crafted request.

Severity

High

CVSS Score

9.1

Exploit Probability

10%

Published Date

April 16, 2026

Template Author

0x_akoko

CVE-2025-4524.yaml
9.1Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE ID:
cve-2025-4524
CWE ID:
cwe-22

References

https://www.wordfence.com/threat-intel/vulnerabilities/id/a3ee01da-218a-421d-8f9c-1dc6c056ef74https://github.com/ptrstr/CVE-2025-4524https://nvd.nist.gov/vuln/detail/CVE-2025-4524https://cxsecurity.com/issue/WLB-2026040012

Remediation Steps

Update to the latest version beyond 2.2.2.