CVE-2018-25437
Cherryframework Cherry Framework Themes
WordPress CherryFramework Themes 3.1.4 contains an information disclosure vulnerability that allows unauthenticated attackers to download sensitive backup files by accessing the download_backup.php endpoint. Attackers can directly access the download_backup.php script in the admin/data_management directory to obtain ZIP archives containing the entire wp-content/themes directory contents.
- CVSS
- 8.7
- EPSS
- 0.29% 20.9% percentile
- CISA KEV
- Not listed
- Published
- 2026.06.15