Junglewise Threat Intelligence

CVE-2025-58707: Axiomthemes Spin local file inclusion in WordPress theme

CVE-2025-58707 · Severity: high · CVSS 8.1 · Published 2026-06-02

Vendors: Axiomthemes.

Executive brief

Axiomthemes Spin, a theme for WordPress websites, contains a security flaw that allows unauthorized individuals to access sensitive files on the web server. By exploiting this vulnerability, an attacker could view configuration files containing database credentials, potentially leading to a full takeover of the website and its data. There is currently no official patch available from the developer.

Technical details

A Local File Inclusion (LFI) vulnerability exists in the Axiomthemes Spin theme for WordPress (versions up to 1.8) due to improper control of filenames in include or require statements (CWE-98). An unauthenticated remote attacker can exploit this by submitting specially crafted requests to include local files from the server. Successful exploitation can lead to the disclosure of sensitive information, such as the wp-config.php file containing database credentials, or potentially remote code execution if the attacker can upload or influence the content of a local file. As of the advisory date, no official patch has been released, and users are advised to use third-party mitigation rules or consider alternative themes.

Affected products

  • Axiomthemes Spin up to 1.8

Timeline

  • 2025-07-31: other: Vulnerability reported by researcher Bonds
  • 2026-05-26: advisory: Initial advisory published by Patchstack
  • 2026-06-02: disclosed: CVE published to NVD

References