CVE-2025-2294
Kubio AI Page Builder <= 2.5.1 - Unauthenticated Local File Inclusion
- Published
- Mar 28, 2025
- Updated
- Apr 8, 2026
- Assigning CNA
- Wordfence
- Evidence observed
- Apr 5, 2025
Primary CVSS
nvd · CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HHigh · next 30 days
- Percentile
- 99.6%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
Summary
The Kubio AI Page Builder plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.5.1 via thekubio_hybrid_theme_load_template function. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.
Sources
10Python PoC for CVE-2025-2294, an unauthenticated Local File Inclusion in the Kubio AI Page Builder WordPress plugin (≤2.5.1), demonstrating arbitrary file disclosure and potential remote code execution.
Proof-of-concept exploit for CVE-2025-2294, a critical LFI vulnerability in Kubio AI Page Builder for WordPress. Includes a Python scanner, nuclei template, and Docker lab for testing.
- CVE-2025-2294Exploit
Unauthenticated Local File Inclusion (LFI) exploit for Kubio Page Builder WordPress plugin (CVE-2025-2294). Supports single target, bulk scanning, version detection, and custom file path reading.
- CVE-2025-2294Exploit
Kubio AI Page Builder <= 2.5.1 - Unauthenticated Local File Inclusion
- CVE-2025-2294Exploit
Python exploit script for CVE-2025-2294, an unauthenticated Local File Inclusion vulnerability in WordPress Kubio AI Page Builder ≤ 2.5.1. Supports single/multi-target scanning, custom payloads, proxy, and response preview.
- CVE-2025-2294Exploit
Kubio AI Page Builder <= 2.5.1 - Unauthenticated Local File Inclusion
- CVE-2025-2294Exploit
Kubio AI Page Builder <= 2.5.1 - Unauthenticated Local File Inclusion
- cve-2025-22294Exploit
the task from C*****k
- CVE-2025-2294Exploit
YAML-based vulnerability scanner for CVE-2025-2294 with active and passive detection templates, enabling automated exploitation checks against Kubio WordPress plugin installations.
4m3rr0r · multiple · Apr 5, 2025
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.