Impact
A PHP Local File Inclusion vulnerability, identified by CWE‑98, allows an attacker to manipulate file names supplied to PHP include/require statements within the Zenny theme. The flaw can enable the attacker to read arbitrary files on the server, and if malicious code is retrieved, it could lead to remote code execution or disclosure of sensitive information. The vulnerability is present in all releases of the theme up to and including version 1.7.5.
Affected Systems
BZOTheme Zenny is affected. All deployments of the theme with a version of 1.7.5 or earlier are vulnerable. No further sub‑versions are listed at this time.
Risk and Exploitability
The CVSS score of 8.1 indicates high severity, yet the EPSS score is below 1%, suggesting a relatively low probability of exploitation in the wild at present. The vulnerability is not listed in CISA’s KEV catalog. The most likely attack vector, inferred from the description, is via a crafted HTTP request that supplies a user‑controlled filename to the vulnerable include/require statement, potentially accessible through publicly visible theme URLs.
OpenCVE Enrichment
EUVD