CVE-2025-2558
CVSS 3.1 Score 6.1 of 10 (medium)
Details
Published Apr 24, 2025
Updated: Apr 29, 2025
CWE ID 89
Summary
CVE-2025-2558 is a vulnerability affecting the The-wound WordPress theme. The issue stems from a failure to validate certain parameters before they are used to construct paths for the include function. This flaw permits unauthenticated users to execute Local File Inclusion (LFI) attacks, potentially enabling the downloading of arbitrary files from the vulnerable server. This vulnerability poses a significant risk, particularly for WordPress sites utilizing the The-wound theme, and immediate remediation is advised to prevent potential exploitation.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.