CVE-2024-6648: Apollotheme Ap Pagebuilder
High severity, CVSS 7.5. EPSS: 0.7% chance of exploitation in the next 30 days.
Absolute Path Traversal vulnerability in AP Page Builder versions prior to 4.0.0 could allow an unauthenticated remote user to modify the 'product_item_path' within the 'config' JSON file, allowing them to read any file on the system.
Affected products
- Apollotheme Ap Pagebuilder: before 4.0.0 (fixed in 4.0.0)
Published 2025-05-08. Last modified 2026-06-17.