Junglewise Threat Intelligence

CVE-2025-57567: PluXml CMS remote code execution in theme editor

CVE-2025-57567 · Severity: critical · CVSS 9.1 · Published 2025-10-17

Technologies: Pluxml, PluXml CMS. Vendors: Pluxml.

Executive brief

PluXml CMS, a lightweight content management system, contains a security flaw in its theme editing tool. An administrative user can modify a specific system file to include malicious code, allowing them to take full control of the underlying web server. This could lead to a complete service outage, theft of sensitive website data, or the use of the server to launch further attacks.

Technical details

A remote code execution (RCE) vulnerability exists within the PluXml CMS theme editor due to improper control of file generation (CWE-94). The flaw is located in the 'minify.php' file within the default theme directory (/themes/defaut/css/minify.php). An attacker with administrative privileges can use the built-in theme editor to overwrite this file with arbitrary PHP code. Because the application does not sufficiently restrict the content or execution of this file, the injected code can be used to execute system-level commands on the host server. This vulnerability requires network access and high-level (Administrator) authentication.

Affected products

  • PluXml PluXml CMS

Timeline

  • 2025-10-17: disclosed
  • 2025-10-17: advisory

References

Related threats