CVE-2025-58206 | ThemeMove MaxCoach Plugin up to 3.2.5 on WordPress filename control
A vulnerability classified as problematic was found in ThemeMove MaxCoach Plugin up to 3.2.5 on WordPress. Impacted is an unknown function. Such manipulation leads to improper control of filename for include/require statement in php program ('php remote file inclusion').
This vulnerability is referenced as CVE-2025-58206. It is possible to launch the attack remotely. No exploit is available.