Impact
The vulnerability is a Path Traversal flaw in the Tastyc theme that allows an attacker to craft input containing sequences like ‘…/…//’ to include arbitrary files through PHP Local File Inclusion. An exploited path traversal can read sensitive files on the server or inject code, potentially exposing credentials, configuration files, or enabling further compromise. This weakness maps to CWE‑35 and provides a direct route to compromise confidentiality or integrity of the website's data and code.
Affected Systems
The issue affects the WordPress Tastyc theme developed by bslthemes. All installations using Tastyc from its earliest release up to, but not including, version 2.5.2 are vulnerable.
Risk and Exploitability
The CVSS score of 8.1 indicates a high severity risk, and the EPSS score of less than 1% suggests a low but non‑zero likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog, implying no confirmed widespread exploitation yet. If the theme is publicly accessible, the likely attack vector is remote file inclusion via crafted request parameters, although no explicit authentication requirement is documented. Exploitation may patch the server with arbitrary code or data leakage depending on the attacker’s goals and the server configuration.
OpenCVE Enrichment
EUVD