Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in UnboundStudio Accordion FAQ allows PHP Local File Inclusion. This issue affects Accordion FAQ: from n/a through 2.2.1.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
CVE-2025-58024 is a PHP Local File Inclusion (LFI) vulnerability affecting UnboundStudio's Accordion FAQ plugin through version 2.2.1. The vulnerability stems from improper control of filenames in PHP include/require statements (CWE-98), allowing attackers to manipulate file paths and include arbitrary local files on the server. This is particularly dangerous in WordPress environments where the plugin is commonly deployed, as attackers can leverage LFI to read sensitive configuration files, database credentials, or other protected content. Any organization using affected versions of Accordion FAQ faces potential information disclosure and lateral movement risks, with the vulnerability requiring minimal or no authentication depending on the plugin's exposure.
While this CVE lacks explicit MITRE ATT&CK mapping, Casky's Claude-powered analysis would correlate it with Techniques like T1083 (File and Directory Discovery) and T1005 (Data from Local System), detecting attack patterns where file inclusion attempts systematically probe for sensitive files. Practitioners using Casky would observe findings related to suspicious include/require parameter manipulation, file path traversal patterns (../ sequences), and attempts to access configuration or credential files. The extended reasoning capabilities would flag the progression from initial reconnaissance to exploitation, helping security teams understand that LFI vulnerabilities often precede more serious compromise. Organizations should immediately audit Accordion FAQ implementations and apply patches to version 2.2.2 or later, while monitoring logs for exploitation attempts targeting common sensitive file paths.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2025-58024. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation