Impact
Improper control of the filename used in a PHP include/require statement exposes Capie to Local File Inclusion. An attacker who can influence the filename may read arbitrary files on the server or, if the files contain PHP code, execute it. This compromises data confidentiality and can lead to remote code execution within the WordPress environment. The flaw maps to CWE‑98.
Affected Systems
ApusTheme’s Capie theme version 1.0.40 and earlier are affected. Sites running these theme versions on WordPress installations are at risk.
Risk and Exploitability
With a CVSS score of 8.1, this issue is considered high severity. The EPSS score of less than 1% indicates that the likelihood of widespread exploitation is low at present, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is likely local or through a crafted request that can influence the include path, so an attacker would need to leverage an input point exposed by the theme. Once triggered, the flaw can lead to sensitive file disclosure or code execution, making it a serious concern for sites still running the impacted theme.
OpenCVE Enrichment
EUVD