Zero Day Monitor
DashboardVulnerabilitiesTrendingZero-DaysNews
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
1887 articles · 106953 vulns · 38/55 feeds (7d)
← Back to list
—
CVE-2026-25458EXPLOITED
Select-Themes · Moments

WordPress Moments theme <= 2.2 - Local File Inclusion vulnerability

Description

A vulnerability described as critical has been identified in Select-Themes Moments Plugin up to 2.2 on WordPress. The impacted element is an unknown function. The manipulation results in improper control of filename for include/require statement in php program ('php remote file inclusion'). This vulnerability is identified as CVE-2026-25458.

Affected Products

VendorProductVersions
Select-ThemesMomentsn/a

References

  • https://patchstack.com/database/Wordpress/Theme/moments/vulnerability/wordpress-moments-theme-2-2-local-file-inclusion-vulnerability?_s_id=cve(vdb-entry)

Related News (1 articles)

Tier C
VulDB4h ago
CVE-2026-25458 | Select-Themes Moments Plugin up to 2.2 on WordPress filename control
→ No new info (linked only)
CISA KEV❌ No
Actively exploited✅ Yes
CWECWE-98
Published3/25/2026
Last enriched4h agov2
Trending Score40
Source articles1
Independent1
Info Completeness7/14
Missing: cvss, epss, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Version History

v2
Last enriched 4h ago
v2Tier C4h ago

Updated severity to CRITICAL, marked as actively exploited, and corrected exploit availability.

descriptionseverityactivelyExploited
via VulDB
v14h ago

Initial creation