CVE-2025-2294 is a Local File Inclusion vulnerability in the Kubio AI Page Builder plugin for WordPress affecting all versions up to and including 2.5.1. The issue is present in the kubio_hybrid_theme_load_template function, which can be abused to include attacker-controlled or otherwise unsafe local files from the server filesystem. Because the vulnerable include path can lead to execution of PHP contained in included files, an unauthenticated attacker may be able to execute arbitrary code from local files present on the server. The flaw can also be leveraged to read sensitive local files and to bypass intended access controls depending on server configuration and available files.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
8 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (2 hidden).
Repository contains a single Python PoC exploit (exploit.py) plus README and LICENSE. The exploit targets CVE-2025-2294: an unauthenticated Local File Inclusion in the WordPress Kubio AI Page Builder plugin (versions <= 2.5.1). Workflow: (1) fetches /wp-content/plugins/kubio/readme.txt and parses the 'Stable tag' to confirm version <= 2.5.1; (2) if vulnerable, sends a GET request to the site root with query parameters __kubio-site-edit-iframe-preview=1 and __kubio-site-edit-iframe-classic-template=<file path>, where the file path is attacker-controlled (default traversal to /etc/passwd); (3) prints the full HTTP response body, which should contain the included file contents. Uses requests.Session with TLS verification disabled and browser-like headers. No reverse shell or post-exploitation is implemented; it is primarily a file-read LFI PoC with a built-in version check.
This repository provides a comprehensive exploitation and detection toolkit for CVE-2025-2294, a critical Local File Inclusion (LFI) vulnerability in the Kubio AI Page Builder WordPress plugin (versions <= 2.5.1). The vulnerability allows unauthenticated remote attackers to include arbitrary files from the server by supplying a crafted value to the '__kubio-site-edit-iframe-classic-template' HTTP parameter, especially when the '__kubio-site-edit-iframe-preview=1' flag is set. The repository contains: - A detailed README.md explaining the vulnerability, exploitation conditions, technical details, and mitigation advice. - A Python script (scan.py) that performs multi-threaded scanning of one or more targets, attempting to exploit the LFI by requesting '/?__kubio-site-edit-iframe-preview=1&__kubio-site-edit-iframe-classic-template=../../../../../../../../../etc/passwd' and checking for evidence of file disclosure (e.g., contents of /etc/passwd). - Two Nuclei templates: 'active.yaml' (actively tests for LFI by attempting to read /etc/passwd) and 'passive.yaml' (checks for vulnerable plugin versions by reading the plugin's readme.txt file). - A docker-compose.yml for quickly setting up a vulnerable WordPress environment for testing. The main exploit capability is unauthenticated LFI, with potential for remote code execution if a PHP file is included. The repository is operational and provides both detection and exploitation tools, with clear network-based attack vectors and fingerprintable HTTP endpoints.
This repository contains a Python exploit script (cve_2025_2294.py) and a detailed README for CVE-2025-2294, a critical unauthenticated Local File Inclusion (LFI) vulnerability in the Kubio AI Page Builder WordPress plugin (versions <= 2.5.1). The exploit works by sending a crafted HTTP GET request to the vulnerable WordPress site, abusing the '__kubio-site-edit-iframe-classic-template' parameter to include arbitrary files from the server. The script supports both single-target and bulk scanning modes, allows custom payloads (default: /etc/passwd), can save full HTTP responses, and supports proxying. The README provides usage instructions, vulnerability details, and example commands. The exploit is operational and can be used to confirm LFI and potentially escalate to remote code execution if file upload is possible. The main entry point is cve_2025_2294.py, which is a standalone Python script.
This repository contains a Python proof-of-concept exploit (lfi.py) and a README for CVE-2025-2294, a critical Local File Inclusion (LFI) vulnerability in the Kubio AI Page Builder WordPress plugin (<= 2.5.1). The exploit script takes a list of target URLs and attempts to exploit the LFI by sending HTTP GET requests with the parameter __kubio-site-edit-iframe-classic-template set to a path traversal payload (e.g., ../../../../../../../etc/passwd). If the response contains evidence of file inclusion (such as the contents of /etc/passwd), the target is marked as vulnerable and its URL is saved to vuln.txt. The script supports multithreading for scanning multiple targets efficiently. The README provides clear usage instructions, vulnerability details, and a curl-based PoC. No fake or destructive actions are present; the exploit is focused on file disclosure via LFI. The main entry point is lfi.py, written in Python.
This repository contains a Python proof-of-concept exploit for CVE-2025-2294, a critical Local File Inclusion (LFI) vulnerability in the Kubio AI Page Builder plugin for WordPress (versions up to 2.5.1). The exploit script, 'CVE-2025-2294.py', reads a list of target domains from 'list.txt' and attempts to access sensitive files such as '/etc/passwd' and web server logs by exploiting a path traversal flaw in the plugin's 'thekubio_hybrid_theme_load_template' function. The script uses multiple threads to efficiently scan multiple targets and logs successful findings to result files. The README provides vulnerability details, usage instructions, and notes that the LFI can potentially be chained to achieve remote code execution. The repository is structured with a single exploit script and a README, and is intended for use by security researchers to verify the presence of the vulnerability on WordPress sites running the affected plugin.
This repository contains a Python exploit script (CVE-2025-2294.py) targeting a Local File Inclusion (LFI) vulnerability in the Kubio AI Page Builder WordPress plugin, versions 2.5.1 and below (CVE-2025-2294). The exploit is unauthenticated and allows attackers to read arbitrary files from the server by abusing the 'kubio_hybrid_theme_load_template' function via crafted GET parameters. The script first checks the plugin version by fetching the readme.txt file, then constructs a malicious URL to include and read a specified file (default: /etc/passwd). The repository also includes a README.md with detailed usage instructions and a LICENSE file. The main entry point is CVE-2025-2294.py, written in Python, and the attack vector is network-based, requiring only HTTP access to the vulnerable WordPress site.
This repository contains a Python exploit script (cve-2025-2994.py) and a README.md for CVE-2025-2294, a Local File Inclusion (LFI) vulnerability in the Kubio Page Builder WordPress plugin (versions <= 2.5.1). The exploit allows unauthenticated attackers to read arbitrary files from the web server by sending specially crafted HTTP GET requests to the target site, leveraging vulnerable parameters in the plugin. The script supports both single-target and bulk-target modes, version detection, and customizable file paths for LFI. The README provides clear usage instructions, options, and example targets. The main attack vector is network-based, targeting HTTP(S) endpoints of WordPress sites running the vulnerable plugin. The exploit is operational, providing real file read capabilities, and is not a detection script or fake exploit.
This repository contains a Python exploit script (CVE-2025-2294.py) targeting a Local File Inclusion (LFI) vulnerability in the Kubio AI Page Builder WordPress plugin (versions <= 2.5.1, CVE-2025-2294). The exploit works by first verifying the plugin version via the publicly accessible readme.txt file, then sending a crafted GET request to the target site with parameters that trigger the LFI vulnerability. By default, it attempts to read /etc/passwd, but any file path can be specified. The script is unauthenticated and requires only network access to the vulnerable WordPress instance. The repository also includes a README.md with detailed usage instructions and a LICENSE file. The exploit is operational, providing file read capabilities but not remote code execution by default.
6 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.