Local File Inclusion in Zagg WooCommerce WordPress Theme by Zagg
CVE-2025-4200
8.1HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 14 June 2025
What is CVE-2025-4200?
The Zagg - Electronics & Accessories WooCommerce WordPress Theme is susceptible to Local File Inclusion vulnerabilities that allow unauthenticated attackers to exploit the load_view() function. This vulnerability is present in all versions up to and including 1.4.1, enabling attackers to include and execute arbitrary files on the server through AJAX actions such as 'load_more_post', 'load_shop', and 'load_more_product'. This could potentially allow attackers to execute PHP code, bypass access controls, and access sensitive data, especially when file uploads involve unverified or deemed 'safe' formats.
Affected Version(s)
Zagg - Electronics & Accessories WooCommerce WordPress Theme * <= 1.4.1