Project Subscriptions
No advisories yet.
Solution
Update the WordPress MaxCoach theme to the latest available version (at least 3.2.6).
Workaround
No workaround given by the vendor.
Wed, 28 Jan 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Thememove
Thememove maxcoach |
|
| CPEs | cpe:2.3:a:thememove:maxcoach:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Thememove
Thememove maxcoach |
Sun, 07 Sep 2025 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wordpress
Wordpress wordpress |
|
| Vendors & Products |
Wordpress
Wordpress wordpress |
Fri, 05 Sep 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 05 Sep 2025 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove MaxCoach allows PHP Local File Inclusion. This issue affects MaxCoach: from n/a through 3.2.5. | |
| Title | WordPress MaxCoach Theme <= 3.2.5 - Local File Inclusion Vulnerability | |
| Weaknesses | CWE-98 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Patchstack
Published:
Updated: 2025-09-05T18:14:40.023Z
Reserved: 2025-08-27T16:19:10.126Z
Link: CVE-2025-58206
Updated: 2025-09-05T18:14:30.329Z
Status : Analyzed
Published: 2025-09-05T17:15:38.903
Modified: 2026-01-28T19:09:37.380
Link: CVE-2025-58206
No data.
OpenCVE Enrichment
Updated: 2025-09-07T15:25:24Z