S4E just found a high claris filemaker server panel detection scanner
critical·Product Based Web Vulnerabilities·Updated Apr 17, 2026

CVE-2025-4524 Scanner

CVE-2025-4524 Scanner - Local File Inclusion vulnerability in WordPress Madara Theme

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
3.2k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2025-4524
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

The Madara – Responsive and modern WordPress theme for manga sites theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.2.2 via the 'template' parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Madara – Responsive and modern WordPress theme for manga sitesby WPStylish
0
Updated Aug 5, 2026View on NVD →
Detail

The WordPress Madara Theme is a widely used theme primarily for manga and comic websites. It enables site owners to manage and present comic content efficiently, incorporating various features suitable for large-scale media hosting. Web developers and site administrators prefer this theme due to its extensive configuration options and modern design aesthetics. However, vulnerabilities in the theme can lead to severe security risks, particularly for sites handling sensitive user data. Ensuring that websites using this theme remain secure is a critical task for administrators and developers. Regularly updating themes and plugins is essential to avoid exposure to known vulnerabilities.

Local File Inclusion (LFI) is a serious vulnerability that allows attackers to include files from the local server through web applications. The vulnerability arises due to improper sanitization of user inputs, particularly in parameters that control file paths. Attackers exploit LFI to execute unauthorized scripts, access restricted directories, or gain information that can be used for further exploits. This vulnerability often leads to unauthorized access to configuration files or sensitive data, exacerbating the security risks posed to vulnerable applications. Detecting and remediating such vulnerabilities is crucial to maintaining the integrity and security of server environments.

The vulnerability in the WordPress Madara Theme involves improper sanitization of the 'template' parameter. An attacker can insert crafted payloads to manipulate file paths, enabling the inclusion of arbitrary files. This particular vulnerability is exploited by sending a POST request to the '/wp-admin/admin-ajax.php' endpoint with the 'template' parameter incorrectly sanitized. The vulnerability can be leveraged to read sensitive files like '/etc/passwd', leading to unauthorized information disclosure. The exploitation requires no authentication, making the attack feasible by remote attackers targeting vulnerable installations.

Exploiting the Local File Inclusion vulnerability can have severe consequences. Attackers can gain access to sensitive server files, leading to unauthorized data disclosure. Additionally, it may permit the execution of arbitrary code, which could compromise the entire web application. With successful exploitation, attackers might bypass access controls and potentially escalate privileges within the server environment. The repercussions include the potential for data breaches, loss of integrity, and unauthorized control over server functionalities. Proactively addressing such vulnerabilities is essential to prevent exploitation and maintain robust security postures.

REFERENCES

Solution Advice
  • Update the WordPress Madara Theme to the latest version beyond 2.2.2.1.
  • Regularly audit and sanitize input parameters to ensure no malicious payloads can be included.
  • Implement file path validation and whitelist acceptable files to reduce potential access to sensitive areas.
  • Use web application firewalls to monitor and block suspicious requests targeting known LFI patterns.
  • Conduct regular security assessments and patch management to stay ahead of emerging vulnerabilities.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.