PluXml CMS Remote Code Execution Vulnerability in Theme Editor

Vulnerability

A remote code execution vulnerability has been identified in the PluXml CMS theme editor, specifically within the minify.php file located in the default theme directory under themes/defaut/css/. This vulnerability allows authenticated administrator users to overwrite the minify.php file with arbitrary PHP code via the admin panel, which can then be executed to run system commands.

Impact

Exploitation of this vulnerability allows for remote code execution on the server, with the executed code running in the context of the web server user.

Added: Oct 17, 2025, 4:20 PM
Updated: Oct 17, 2025, 4:20 PM

Vulnerability Rating

Custom Algorithm
spread
1.0
impact
10.0
exploitability
5.0
remediation
0.0
relevance
0.8
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.