PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Apr 9, 2026

WordPress The Wound Theme <= 0.0.1 - Local File Inclusion

Est. Time~10 seconds
Scan TypeGroup Scan
Targetsurl
CostFree
2.5k
Times Used
continuous scan runs
0
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2025-2558
8.6
CVSShigh
Exploitable remotely over the internet · no authentication required.

The-wound WordPress theme through 0.0.1 does not validate some parameters before using them to generate paths passed to include function/s, allowing unauthenticated users to perform LFI attacks and download arbitrary file from the server

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
the-wound
0
Updated Sep 9, 2026View on NVD →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

WordPress The Wound Theme <= 0.0.1 - Local File Inclusion Scanner | S4E