Impact
Improper control of the filename in include/require statements allows local file inclusion. An attacker can use crafted input to read arbitrary files on the server or execute PHP code stored locally, potentially leading to data exposure, tampering, or full code execution. The weakness is identified as CWE-98 and carries a CVSS score of 8.1, indicating high severity.
Affected Systems
The SNS Anton WordPress theme is affected. All releases from the first available version through version 4.1 are vulnerable. Any WordPress installation that uses SNS Anton <=4.1 is at risk.
Risk and Exploitability
The CVSS score highlights a serious risk, while the EPSS score of <1% suggests that exploitation is currently uncommon. The vulnerability is not listed in the CISA KEV catalog. Attackers would need to manipulate file path parameters that the theme includes, and the lacking safeguards can lead to local file inclusion. Given the high impact and the possibility of remote code execution, administrators should treat this as a priority flaw even though exploitation probability appears low at present.
OpenCVE Enrichment
EUVD