A remote code execution (RCE) vulnerability exists in the PluXml CMS theme editor, specifically in the minify.php file located under the default theme directory (/themes/defaut/css/minify.php). An authenticated administrator user can overwrite this file with arbitrary PHP code via the admin panel, enabling execution of system commands.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 21 Oct 2025 13:15:00 +0000

Type Values Removed Values Added
First Time appeared Pluxml
Pluxml pluxml
Vendors & Products Pluxml
Pluxml pluxml

Fri, 17 Oct 2025 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-94
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 17 Oct 2025 15:45:00 +0000

Type Values Removed Values Added
Description A remote code execution (RCE) vulnerability exists in the PluXml CMS theme editor, specifically in the minify.php file located under the default theme directory (/themes/defaut/css/minify.php). An authenticated administrator user can overwrite this file with arbitrary PHP code via the admin panel, enabling execution of system commands.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2025-10-17T15:45:59.167Z

Reserved: 2025-08-17T00:00:00.000Z

Link: CVE-2025-57567

cve-icon Vulnrichment

Updated: 2025-10-17T15:45:05.275Z

cve-icon NVD

Status : Received

Published: 2025-10-17T16:15:38.373

Modified: 2025-10-17T16:15:38.373

Link: CVE-2025-57567

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-10-21T13:09:19Z