Skip to content

Known CVE

WordPress The Wound Theme <= 0.0.1 - Local File Inclusion

The-wound WordPress theme through 0.0.1 contains a local file inclusion caused by insufficient validation of parameters used to generate paths passed to include functions, letting unauthenticated users perform LFI attacks and download arbitrary files from the server.

CVE-2025-2558

High2025CVSS 8.6CWE-98

cve2025 · wordpress · wp-theme · lfi · the-wound · wpscan · vuln

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website