← Back to browse · API

CVE-2025-2294

Severity
CRITICAL
CVSS
9.8
EPSS
0.7788
Risk score
66.46
CISA KEV
No
PoC
No
Published
2025-03-28
Modified
2026-04-08
First seen
2026-08-07
Aliases
EUVD-2025-15115, GHSA-8FP6-H7XC-PJF2
Products
ExtendThemes:Kubio AI Page Builder 0 ≤2.5.1
Sources
euvd EUVD-2025-15115

Description

The Kubio AI Page Builder plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.5.1 via thekubio_hybrid_theme_load_template function. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.

References