Impact
The vulnerability is an improper control of the filename parameter used in a PHP include/require statement, allowing local file inclusion. If exploited, attackers could read arbitrary files on the web server or trigger execution of malicious PHP code, resulting in data exposure, defacement, or full server compromise. This weakness is classified as CWE‑98.
Affected Systems
WordPress sites using the Nitan theme up to and including version 2.9 are affected. The theme is distributed by the vendor snstheme under the product name Nitan. All installations of Nitan up to and including version 2.9 are vulnerable.
Risk and Exploitability
The CVSS score of 8.1 indicates a high severity. The EPSS score of less than 1 % shows a very low likelihood of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that attackers could potentially exploit the flaw by supplying a crafted filename through a web request that triggers a PHP include/require. Successful exploitation would allow reading sensitive files or executing arbitrary PHP code, granting the attacker significant control over the affected WordPress site.
OpenCVE Enrichment
EUVD