Local File Inclusion in Zagg WooCommerce WordPress Theme by Zagg
CVE-2025-4200

8.1HIGH

What is CVE-2025-4200?

The Zagg - Electronics & Accessories WooCommerce WordPress Theme is susceptible to Local File Inclusion vulnerabilities that allow unauthenticated attackers to exploit the load_view() function. This vulnerability is present in all versions up to and including 1.4.1, enabling attackers to include and execute arbitrary files on the server through AJAX actions such as 'load_more_post', 'load_shop', and 'load_more_product'. This could potentially allow attackers to execute PHP code, bypass access controls, and access sensitive data, especially when file uploads involve unverified or deemed 'safe' formats.

Affected Version(s)

Zagg - Electronics & Accessories WooCommerce WordPress Theme * <= 1.4.1

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nguyen Tan Phat
.
CVE-2025-4200 : Local File Inclusion in Zagg WooCommerce WordPress Theme by Zagg