Impact
An improper control of filename in the QantumThemes Typify theme allows an attacker to include local files via PHP’s include/require statement. This flaw can lead to disclosure of sensitive configuration or system files, compromising the confidentiality, integrity, and availability of the underlying WordPress site.
Affected Systems
The vulnerability affects all instances of the QantumThemes Typify theme with versions n/a through 3.0.2. Any WordPress site still running a version of this theme older than 3.0.3 is susceptible.
Risk and Exploitability
The CVSS score of 8.1 indicates high severity. The EPSS value of less than 1% suggests a low but nonzero likelihood of exploitation, and the flaw is not currently listed in CISA’s KEV catalog. Based on the description, it is inferred that a remote attacker can trigger the inclusion by sending a specially crafted request that causes the theme to include an arbitrary local file. Successful exploitation would allow the attacker to read sensitive files.
OpenCVE Enrichment