Impact
The Ark Theme Core plugin contains an improper control of code generation flaw, allowing an attacker to inject and execute arbitrary PHP code on the host. This results in complete compromise of the WordPress site, exposing all data and granting full control to the attacker.
Affected Systems
WordPress sites that have the Ark Theme Core plugin from FRESHFACE with a version earlier than 1.71.0 are vulnerable. No other vendors are listed.
Risk and Exploitability
An unauthenticated attacker can exploit this flaw by sending a crafted payload to the vulnerable plugin, achieving remote code execution with the privileges of the web server process. The CVSS score of 10 signals critical severity, while the EPSS score of <1% indicates a low current likelihood of exploitation. The vulnerability is not included in the CISA KEV catalog, yet the high impact and unauthenticated nature make it a top priority for immediate remediation.
OpenCVE Enrichment
EUVD