Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 23 Jun 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Cherryframework
Cherryframework cherry Framework Themes Wordpress Wordpress wordpress |
|
| Vendors & Products |
Cherryframework
Cherryframework cherry Framework Themes Wordpress Wordpress wordpress |
Mon, 15 Jun 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 15 Jun 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | WordPress CherryFramework Themes 3.1.4 contains an information disclosure vulnerability that allows unauthenticated attackers to download sensitive backup files by accessing the download_backup.php endpoint. Attackers can directly access the download_backup.php script in the admin/data_management directory to obtain ZIP archives containing the entire wp-content/themes directory contents. | |
| Title | WordPress CherryFramework Themes 3.1.4 Backup File Download | |
| Weaknesses | CWE-306 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-06-15T19:24:18.908Z
Reserved: 2026-06-15T11:35:04.298Z
Link: CVE-2018-25437
Updated: 2026-06-15T15:22:00.486Z
Status : Deferred
Published: 2026-06-15T14:16:32.367
Modified: 2026-06-15T20:50:47.973
Link: CVE-2018-25437
No data.
OpenCVE Enrichment
Updated: 2026-06-23T21:09:09Z