Impact
The Kubio AI Page Builder plugin for WordPress contains an unauthenticated local file inclusion flaw in the kubio_hybrid_theme_load_template function. This allows an attacker to include and execute arbitrary files on the server, thereby running any PHP code. The ability to run code can bypass access controls, retrieve sensitive data, or provide full code execution if an attacker can upload files that appear safe, such as images.
Affected Systems
The affected product is extendthemes Kubio AI Page Builder. Versions up to and including 2.5.1 are vulnerable.
Risk and Exploitability
The vulnerability has a CVSS score of 9.8, highlighting its high severity, and an EPSS of 78%, indicating a considerable probability of exploitation. It is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is that an unauthenticated attacker can upload a malicious script or point to a local file, and then trigger its inclusion through the vulnerable function, resulting in remote code execution on the affected WordPress site.
OpenCVE Enrichment