CVE-2024-6648: Apollotheme Ap Pagebuilder

High severity, CVSS 7.5. EPSS: 0.7% chance of exploitation in the next 30 days.

Absolute Path Traversal vulnerability in AP Page Builder versions prior to 4.0.0 could allow an unauthenticated remote user to modify the 'product_item_path' within the 'config' JSON file, allowing them to read any file on the system.

Affected products

  • Apollotheme Ap Pagebuilder: before 4.0.0 (fixed in 4.0.0)

Published 2025-05-08. Last modified 2026-06-17.