Impact
The vulnerability arises from improper validation of the filename used in an include/require statement within the ApusTheme Butcher WordPress theme. Because the theme accepts unsanitized input, a user can supply a crafted path that causes the server to include an arbitrary local file. This Local File Inclusion (CWE‑98) can lead to unintended disclosure of sensitive files, code execution, or further exploitation.
Affected Systems
It affects the ApusTheme Butcher theme for WordPress, specifically versions up to and including 2.40. The problem exists from the initial release through version 2.40. Any WordPress installation using a vulnerable version of this theme is at risk.
Risk and Exploitability
The CVSS score is 8.1, indicating high impact. The EPSS score is below 1 %, suggesting low current exploitation probability, and the vulnerability is not listed in CISA KEV. Attackers would exploit the flaw by sending a request that manipulates the filename parameter, potentially without authentication. If successful, the attacker could read sensitive files or execute code on the server, compromising confidentiality, integrity, and availability of the affected website.
OpenCVE Enrichment
EUVD