
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-58936 is a PHP Local File Inclusion (LFI) vulnerability in the Axiomthemes Catamaran WordPress theme, classified under CWE-98 (Improper Control of Filename for Include/Require Statement). It affects all versions of the Catamaran theme up to and including version 1.15. The vulnerability was reported on July 23, 2025, by researcher "Bonds" and published by Patchstack on August 22, 2025. It carries a CVSS v3.1 base score of 8.1 (High), exploitable remotely without authentication (Patchstack).
The root cause is improper validation of user-supplied input used in PHP include/require statements within the Catamaran WordPress theme (CWE-98). An unauthenticated remote attacker can manipulate filename parameters to cause the server to include arbitrary local files, potentially exposing their contents. The attack vector is network-based with high attack complexity and requires no privileges or user interaction. No public proof-of-concept code has been identified at this time (Patchstack, Feedly).
Successful exploitation allows an attacker to read sensitive files on the server, including configuration files containing database credentials (e.g., WordPress wp-config.php), which could lead to complete database takeover. Depending on server configuration, the vulnerability may also enable arbitrary code execution by including files with attacker-controlled content. The confidentiality, integrity, and availability impacts are all rated High, making this a significant risk for any WordPress site running the affected theme (Patchstack).
No public proof-of-concept exploit or evidence of active in-the-wild exploitation has been confirmed as of the time of publication. The EPSS score is approximately 0.053%, indicating a low current probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, Patchstack classifies it as high priority, noting that vulnerabilities of this type are commonly used in mass-exploit campaigns targeting WordPress sites regardless of traffic or popularity (Patchstack).
../../../../wp-config.php) targeting the vulnerable parameter to include sensitive local files.wp-config.php or other configuration files.../, ..%2F, %2e%2e%2f) in query parameters or POST body.wp-config.php, /etc/passwd, or PHP session files by the web server process.As of the publication date, no official patch from Axiomthemes is available for the Catamaran theme. Patchstack has issued a virtual patching/mitigation rule for its users to block exploitation attempts until an official fix is released. Site owners should update the Catamaran theme to any version beyond 1.15 if and when a patched release becomes available, conduct a security audit of the WordPress installation, and implement additional input validation for file inclusion operations. In the interim, consider using a web application firewall (WAF) or the Patchstack plugin to apply the available mitigation rule (Patchstack).
Patchstack, which discovered and disclosed the vulnerability through researcher "Bonds," has classified it as high priority and issued a virtual mitigation rule for its platform users. No significant broader media coverage or notable researcher commentary beyond the Patchstack advisory has been identified at this time (Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."