The-wound WordPress theme through 0.0.1 contains a local file inclusion caused by insufficient validation of parameters used to generate paths passed to include functions, letting unauthenticated users perform LFI attacks and download arbitrary files from the server.
id: CVE-2025-2558
info:
name: WordPress The Wound Theme <= 0.0.1 - Local File Inclusion
author:
...