
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-58932 is a Local File Inclusion (LFI) vulnerability in the Axiomthemes Prisma WordPress theme that allows unauthenticated remote attackers to include arbitrary local files on the server. It affects all versions of the Prisma theme through version 1.10. The vulnerability was reported by researcher "Bonds" on July 23, 2025, and published by Patchstack on August 22, 2025. It carries a CVSS v3.1 base score of 8.1 (High) (Patchstack).
The vulnerability is classified as CWE-98 (Improper Control of Filename for Include/Require Statement in PHP Program), which manifests when user-supplied input is passed unsanitized to PHP include or require statements within the Prisma theme. An unauthenticated attacker can craft a network request that manipulates the filename parameter to traverse the file system and include sensitive local files. No authentication or user interaction is required, though the attack complexity is rated High, suggesting some precondition or bypass technique may be needed (Patchstack).
Successful exploitation allows an attacker to read arbitrary files from the web server's file system, including sensitive configuration files such as wp-config.php (which contains database credentials), /etc/passwd, and other system files. Exposure of database credentials could lead to complete database takeover, and further lateral movement within the hosting environment is possible depending on server configuration. Confidentiality, integrity, and availability are all rated as High impact (Patchstack).
No public proof-of-concept exploit code has been identified, and there is no evidence of active in-the-wild exploitation at this time. The vulnerability requires no authentication and no user interaction, making it attractive for mass-exploit campaigns targeting WordPress sites. The EPSS score is approximately 0.053% (0.000530), indicating a currently low but non-negligible probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Patchstack notes that vulnerabilities of this class are commonly used in mass-exploit campaigns against WordPress sites regardless of traffic size (Patchstack).
include/require statement without proper sanitization.../../../../wp-config.php or ../../../../etc/passwd) to reference sensitive local files.wp-config.php, which can then be used for further attacks such as database access or privilege escalation (Patchstack).../, ..%2F, %2e%2e%2f) in query parameters or form fields.As of the publication date, no official patch from Axiomthemes is available for the Prisma theme. Site owners running Prisma version 1.10 or earlier should consider deactivating or replacing the theme until a patched version is released. Patchstack has issued a virtual patching/mitigation rule for its subscribers to block exploitation attempts in the interim. Additionally, deploying a Web Application Firewall (WAF) with rules to detect and block path traversal and LFI patterns is recommended as a compensating control (Patchstack).
Patchstack, which discovered and disclosed the vulnerability through researcher "Bonds," has rated it as high priority and noted that vulnerabilities of this class are frequently leveraged in mass-exploit campaigns against WordPress sites. No significant vendor statement from Axiomthemes, broader media coverage, or notable social media discussion has been identified at this time (Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."