Impact
The Opstore theme for WordPress, versions up to 1.4.5, contains an improper control of filenames for PHP include/require statements. An attacker can supply a crafted path that forces the server to include local files, potentially revealing sensitive information and allowing arbitrary code execution when the included file contains malicious PHP. This flaw satisfies the conditions of CWE‑98 and can jeopardize the confidentiality, integrity, and availability of the affected WordPress installation.
Affected Systems
The vulnerability affects the Opstore theme distributed by wpoperations. Every instance of the theme deployed in a WordPress environment with a version number of 1.4.5 or earlier is susceptible, regardless of configuration.
Risk and Exploitability
The CVSS score of 7.5 indicates a medium‑to‑high severity risk, and the EPSS score of less than 1 % suggests that widespread exploitation is currently unlikely, though the flaw is still exploitable by an adversary with sufficient access. The vulnerability is not listed in the CISA KEV catalog, meaning no publicly known exploits are recorded, but the local file inclusion path provides a clear attack vector once the attacker can influence the include statement, typically via web input, file uploads, or misconfigured directories. Immediate patching is the recommended mitigation step.
OpenCVE Enrichment
EUVD