Impact
A vulnerability in the Gavias Kiamo – Responsive Business Service WordPress Theme permits the inclusion of arbitrary files controlled by the attacker. The flaw arises from unvalidated filename inputs in PHP include/require statements, enabling read or execution of sensitive files. The primary consequence is loss of data confidentiality and potential compromise of the host system if executable content is included.
Affected Systems
The vulnerability affects the Gavias Kiamo theme used in WordPress installations, covering all releases up to version 1.3.3. Users running these versions of the theme are at risk regardless of other site configurations.
Risk and Exploitability
The CVSS score of 8.1 points to high severity, while the EPSS score of less than 1% suggests a low current exploitation probability. The vulnerability is not listed in CISA’s KEV catalog. The attack vector is likely remote, with an adversary exploiting the theme when it processes user-supplied input, but the exact conditions are not fully detailed in the available description.
OpenCVE Enrichment
EUVD