header-logo
Suggest Exploit
vendor:
Kubio AI Page Builder
by:
Sheikh Mohammad Hasan
6.1
CVSS
HIGH
Local File Inclusion (LFI)
22
CWE
Product Name: Kubio AI Page Builder
Affected Version From: 2.5.2001
Affected Version To: 2.5.2001
Patch Exists: NO
Related CWE: CVE-2025-2294
CPE: a:wordpress:kubio:2.5.1
Metasploit:
Platforms Tested: WordPress 6.4.2 (Ubuntu 22.04 LTS)
2025

Kubio AI Page Builder <= 2.5.1 - Local File Inclusion (LFI)

The Kubio AI Page Builder plugin for WordPress version 2.5.1 and below is vulnerable to Local File Inclusion (LFI) in the `kubio_hybrid_theme_load_template` function. This allows unauthorized attackers to read arbitrary files through path traversal, potentially leading to Remote Code Execution (RCE) when combined with file upload capabilities.

Mitigation:

Update to version 2.5.2 or later to mitigate this vulnerability. Avoid untrusted file uploads and ensure proper input validation to prevent LFI attacks.
Source

Exploit-DB raw data: