CVE-2025-1611

CVSS 3.1 Score 4.7 of 10 (medium)

Details

Published Feb 24, 2025
CWE ID 707
CWE ID 74

Summary

CVE-2025-1611 is a newly disclosed vulnerability affecting ShopXO up to version 6.4.0. The issue lies in the Template Handler's app/service/ThemeAdminService.php file and has been classified as problematic. This vulnerability allows for remote code injection, making it a significant security concern. The exploit for this vulnerability has been made public, increasing the risk for potential attacks. Despite early notification, the vendor has yet to respond or provide a patch.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share