CVE-2025-58206: WordPress MaxCoach Theme <= 3.2.5 - Local File Inclusion Vulnerability
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove MaxCoach maxcoach allows PHP Local File Inclusion.This issue affects MaxCoach: from n/a through <= 3.2.5.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-58206?
CVE-2025-58206 has been classified with a severity rating that indicates a risk of Local File Inclusion, potentially leading to unauthorized access.
How do I fix CVE-2025-58206?
To mitigate CVE-2025-58206, upgrade ThemeMove MaxCoach to version 3.2.6 or later where the vulnerability is addressed.
What types of attacks can CVE-2025-58206 facilitate?
CVE-2025-58206 can facilitate Local File Inclusion attacks, which may allow an attacker to execute arbitrary local files.
Which versions of ThemeMove MaxCoach are affected by CVE-2025-58206?
CVE-2025-58206 affects all versions of ThemeMove MaxCoach from n/a up to and including version 3.2.5.
Is CVE-2025-58206 present in the WordPress MaxCoach Theme?
Yes, CVE-2025-58206 is present in the WordPress MaxCoach Theme up to version 3.2.5.