CVE-2025-2558

CVSS 3.1 Score 6.1 of 10 (medium)

Details

Published Apr 24, 2025
Updated: Apr 29, 2025
CWE ID 89

Summary

CVE-2025-2558 is a vulnerability affecting the The-wound WordPress theme. The issue stems from a failure to validate certain parameters before they are used to construct paths for the include function. This flaw permits unauthenticated users to execute Local File Inclusion (LFI) attacks, potentially enabling the downloading of arbitrary files from the vulnerable server. This vulnerability poses a significant risk, particularly for WordPress sites utilizing the The-wound theme, and immediate remediation is advised to prevent potential exploitation.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share