Known CVE
WordPress The Wound Theme <= 0.0.1 - Local File Inclusion
The-wound WordPress theme through 0.0.1 contains a local file inclusion caused by insufficient validation of parameters used to generate paths passed to include functions, letting unauthenticated users perform LFI attacks and download arbitrary files from the server.
CVE-2025-2558
High2025CVSS 8.6CWE-98
cve2025 · wordpress · wp-theme · lfi · the-wound · wpscan · vuln
Verified scans run this check after you prove you own the site.
All known CVEsView the checks catalogNational Vulnerability Database
Scan a website