CVE-2025-2101
Last modified
CVE-2025-2101 is a high-severity vulnerability rated 8.1/10 on the CVSS scale. The Edumall theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.2.4 via the 'template' parameter of the 'edumall_lazy_load_template' AJAX action. This makes it possible for unauthenticated attackers to include and execute arbitrary PHP files on the server, allowing the execution of any PHP code in those files. EPSS estimates a 0.74% chance of exploitation in the next 30 days.
Description
The Edumall theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.2.4 via the 'template' parameter of the 'edumall_lazy_load_template' AJAX action. This makes it possible for unauthenticated attackers to include and execute arbitrary PHP files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where PHP files can be uploaded and included.
Metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-2101?
How severe is CVE-2025-2101?
How do I fix CVE-2025-2101?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-21004Improper verification of intent by broadcast receiver in Sys…5.5
- CVE-2025-21005Improper access control in isemtelephony prior to Android 15…5.5
- CVE-2025-21006Out-of-bounds write in handling of macro blocks for MPEG4 co…7.8
- CVE-2025-21007Out-of-bounds write in accessing uninitialized memory in lib…5.5
- CVE-2025-21008Out-of-bounds read in decoding frame header in libsavsvc.so …5.5
- CVE-2025-21009Out-of-bounds read in decoding malformed frame header in lib…5.5
- CVE-2025-21010Improper privilege management in SamsungAccount prior to SMR…6
- CVE-2025-21011Improper access control in SemSensorService for Galaxy Watch…5.5
- CVE-2025-21012Improper access control in fall detection for Galaxy Watch p…5.5
- CVE-2025-21013Improper access control in SemSensorManager for Galaxy Watch…6.2
- CVE-2025-21014Improper export of android application component in Emergenc…5.5
- CVE-2025-21015Path Traversal in Document scanner prior to SMR Aug-2025 Rel…7.1
Are you affected by CVE-2025-2101?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
