High severity7.5NVD Advisory· Published Jun 15, 2026· Updated Jun 15, 2026
CVE-2018-25437
CVE-2018-25437
Description
WordPress CherryFramework Themes 3.1.4 contains an information disclosure vulnerability that allows unauthenticated attackers to download sensitive backup files by accessing the download_backup.php endpoint. Attackers can directly access the download_backup.php script in the admin/data_management directory to obtain ZIP archives containing the entire wp-content/themes directory contents.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2=3.1.4+ 1 more
- (no CPE)range: =3.1.4
- (no CPE)range: = 3.1.4
Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.