Impact
An unauthenticated Local File Inclusion flaw exists in the WordPress Shuffle Theme versions 1.8 and earlier. The vulnerability, classified as CWE-98, allows an attacker to reference arbitrary files on the server by manipulating the theme’s file paths. This can expose sensitive configuration data, database credentials, or other confidential information, and may enable execution of injected code if the files are interpreted by the PHP runtime.
Affected Systems
The flaw affects WordPress installations that include the Shuffle Theme from Edge Themes. Any site running version 1.8 or earlier is vulnerable; no other WordPress themes or core components are implicated by the current disclosure.
Risk and Exploitability
The CVSS base score of 8.1 denotes a high severity vulnerability. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, but these factors do not mitigate the potential impact. The likely attack vector is through the theme’s file path handling, requiring only the ability to manipulate a URL parameter or theme setting accessible to unauthenticated users. An attacker with network access to the web server could exploit the flaw with minimal prerequisites, potentially leading to data disclosure, log tampering, or remote code execution if crafted files are placed in accessible directories.
OpenCVE Enrichment