Arbitrary File Upload Vulnerability in AIHub Theme for WordPress
CVE-2025-1093

9.8CRITICAL

Key Information:

Vendor
Liquidthemes
Status
Ai Hub - Startup & Technology WordPress Theme
Vendor
CVE Published:
19 April 2025

Summary

The AIHub theme for WordPress has a vulnerability that allows unauthorized file uploads due to a lack of proper file type validation in the generate_image function. This issue affects all versions up to 1.3.7, enabling potential attackers to upload arbitrary files to the affected server, which poses a risk for remote code execution. It is crucial for users to update to a secure version to mitigate these risks.

Affected Version(s)

AI Hub - Startup & Technology WordPress Theme * <= 1.3.7

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Friderika Baranyai
.