PT-2025-42618 · Unknown · Pluxml Cms
Published
2025-10-17
·
Updated
2025-10-22
·
CVE-2025-57567
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
PluXml CMS (affected versions not specified)
Description
A remote code execution (RCE) issue exists in PluXml CMS within the theme editor functionality. The flaw is located in the
minify.php file, found in the default theme directory (/themes/defaut/css/minify.php). An authenticated administrator user can overwrite this file with arbitrary PHP code through the admin panel, allowing for the execution of system commands. The minify.php file is vulnerable to being overwritten with malicious code.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
RCE
Improper Access Control
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Pluxml Cms