
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-58945 is a Local File Inclusion (LFI) vulnerability in the EcoGrow WordPress theme developed by Axiomthemes, classified under CWE-98 (Improper Control of Filename for Include/Require Statement in PHP Program). It affects EcoGrow versions up to and including 1.7, allowing unauthenticated remote attackers to include arbitrary local files on the server. The vulnerability was reported on August 3, 2025, and published by Patchstack on September 2, 2025. It carries a CVSS v3.1 base score of 8.1 (High) (Patchstack).
The root cause is improper control of filename parameters used in PHP include/require statements within the EcoGrow theme (CWE-98), which allows user-supplied input to influence which local file is included and executed. An unauthenticated attacker can craft a network request that manipulates a file path parameter, causing the server to include and render arbitrary local files — such as configuration files or credential stores — without any authentication or user interaction required. The attack complexity is rated High, suggesting some precondition or non-trivial exploitation step is involved (e.g., specific server configuration or path traversal constraints). No public proof-of-concept code has been identified at this time (Patchstack, Feedly).
Successful exploitation allows a remote, unauthenticated attacker to read arbitrary files from the web server's filesystem, including sensitive files such as wp-config.php (containing database credentials), server configuration files, and other site data. This can result in full database compromise, credential theft, and potential escalation to broader system access depending on server configuration. The vulnerability has a high impact on confidentiality, integrity, and availability (Patchstack).
As of the time of publication, there is no known public proof-of-concept exploit and no confirmed evidence of in-the-wild exploitation. The EPSS score is approximately 0.053%, indicating a low current probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Patchstack has noted that vulnerabilities of this class are commonly used in mass-exploit campaigns targeting WordPress sites at scale (Patchstack).
As of the Patchstack advisory, no official patch from the theme developer (Axiomthemes) is available for EcoGrow. Site owners should upgrade to a version greater than 1.7 if and when one becomes available, or consider replacing the theme. In the interim, Patchstack has issued a virtual patching/mitigation rule for its subscribers to block exploitation attempts. Additionally, deploying a Web Application Firewall (WAF) configured to detect and block file inclusion attack patterns, and implementing strict input validation on file path parameters, are recommended compensating controls (Patchstack).
Patchstack, which discovered and disclosed the vulnerability (credited to researcher 'Bonds'), has classified it as high priority and noted that LFI vulnerabilities of this type are frequently leveraged in mass WordPress exploitation campaigns. No significant broader media coverage or notable researcher commentary beyond the Patchstack advisory has been identified (Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."