Impact
The Evon theme for WordPress contains an improper control of the filename used in PHP include/require statements, classified as a Local File Inclusion flaw under CWE‑98. The vulnerability allows an attacker to manipulate the file path parameter and include arbitrary local files on the server. If files containing executable code are included, an attacker could run arbitrary PHP code, leading to full compromise of the affected WordPress installation.
Affected Systems
Affected users run the snstheme Evon theme, version 3.4 or earlier. The vulnerability applies to all releases from the initial version up to and including 3.4. WordPress sites that have not upgraded beyond 3.4 are at risk.
Risk and Exploitability
With a CVSS score of 8.1 the issue is considered high severity, while the current EPSS score of less than 1% indicates that, as of the latest data, exploitation attempts are rare. The vulnerability is not listed in CISA KEV, but the potential for remote code execution makes it a priority for rapid remediation. Attackers would need only to supply a crafted file path to a vulnerable include call, typically via a public endpoint or malicious user input.
OpenCVE Enrichment
EUVD