Local File Inclusion in Zagg WooCommerce WordPress Theme by Zagg
CVE-2025-4200
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 14 June 2025
What is CVE-2025-4200?
The Zagg - Electronics & Accessories WooCommerce WordPress Theme is susceptible to Local File Inclusion vulnerabilities that allow unauthenticated attackers to exploit the load_view() function. This vulnerability is present in all versions up to and including 1.4.1, enabling attackers to include and execute arbitrary files on the server through AJAX actions such as 'load_more_post', 'load_shop', and 'load_more_product'. This could potentially allow attackers to execute PHP code, bypass access controls, and access sensitive data, especially when file uploads involve unverified or deemed 'safe' formats.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Zagg - Electronics & Accessories WooCommerce WordPress Theme * <= 1.4.1
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved