CVE-2018-25437 HIGH

CVE-2018-25437: WordPress CherryFramework Themes 3.1.4 Backup File Download

Vendor Cherryframework
Product Cherry Framework Themes
Weakness CWE-306 · Missing auth
Published June 15, 2026
Last update June 15, 2026

CVSS base score

8.7/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

What the vulnerability does

Description

WordPress CherryFramework Themes 3.1.4 contains an information disclosure vulnerability that allows unauthenticated attackers to download sensitive backup files by accessing the download_backup.php endpoint. Attackers can directly access the download_backup.php script in the admin/data_management directory to obtain ZIP archives containing the entire wp-content/themes directory contents.

Key dates

Disclosure timeline

June 15, 2026 CVE published
June 15, 2026 Record updated