S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Apr 16, 2025

CVE-2025-2294 Scanner

CVE-2025-2294 Scanner - Local File Inclusion (LFI) vulnerability in Kubio AI Page Builder

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
2.9k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2025-2294
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

The Kubio AI Page Builder plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.5.1 via thekubio_hybrid_theme_load_template function. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Kubio AI Page Builderby extendthemes
0
Updated Aug 22, 2026View on NVD →
Detail

The Kubio AI Page Builder is a popular plugin used by WordPress site administrators to facilitate theme customization through an automated AI-driven interface. It is utilized by bloggers, businesses, and web developers to create and edit pages on their WordPress websites with ease. By integrating AI technology, Kubio AI Page Builder streamlines the page design process, allowing users to create aesthetically pleasing and functionally robust web pages without extensive coding knowledge. The plugin is widely considered an asset for WordPress users looking to enhance their site's functionality and appearance efficiently. It is often recommended for small to medium-sized businesses aiming to professionalize their online presence.

The Local File Inclusion (LFI) vulnerability is a serious security flaw that permits unauthorized users to execute arbitrary files on a server. By exploiting the vulnerability, attackers can use file paths to load and run potentially malicious scripts. This can happen when the application does not properly validate or sanitize user inputs. The vulnerability is prevalent in web applications and can be triggered by manipulating path traversal mechanisms. Attackers leveraging this vulnerability can gain unauthorized access to sensitive files and possibly execute code on the server, making it a critical threat.

Technical details of the vulnerability include an insecure function named kubio_hybrid_theme_load_template, which is responsible for loading templates within the plugin. An attacker can exploit this function by crafting URLs with path traversal sequences to access unauthorized files. Blindly loading these files poses a risk as it could execute code within them, given the right conditions. The endpoint is equipped to accept paths that lead to critical server files, leading to the potential execution of arbitrary PHP code. Attackers can also exploit this to bypass certain access controls or retrieve sensitive data.

Exploitation of this Local File Inclusion vulnerability can lead to severe consequences, such as unauthorized data access, file modification, or site defacement. In the worst-case scenario, attackers could execute malicious scripts, causing a total compromise of the affected system. The attack might completely bypass access controls and allow arbitrary code execution, potentially leading to data breaches and a loss of sensitive information. This can result in significant damage to the site's integrity and trust with its users.

REFERENCES

Solution Advice
  • Upgrade the Kubio AI Page Builder plugin to version 2.5.2 or later.
  • Regularly update plugins and themes to their latest versions to patch security vulnerabilities.
  • Conduct periodic security audits on WordPress sites to detect and fix vulnerabilities promptly.
  • Utilize security plugins designed to bolster WordPress defenses against known vulnerabilities like LFI.
  • Restrict file permissions to limit access to sensitive directories and files on the server.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.