Impact
The flaw allows anyone accessing the site to supply an arbitrary filename to an include or require statement in the Nasa Core plugin. By manipulating the filename parameter, an attacker can read any file accessible to the web server, such as configuration files, user data, or application secrets. The description does not confirm that arbitrary PHP code can be executed, but if a PHP file is included and executed, further code execution could result. The vulnerability is restricted to the environment running the affected plugin, but exposure of critical files could compromise the entire site.
Affected Systems
WordPress installations that have the Nasa Core plugin (developed by NasaTheme) at any version up through 6.3.2 are vulnerable. The plugin is available to any WordPress site that chooses to install it and therefore can be present on both small personal blogs and large commercial sites.
Risk and Exploitability
The CVSS score of 8.1 signals a high severity vulnerability. The EPSS score of less than 1% indicates that exploitation is currently unlikely, and the issue is not listed in CISA’s KEV catalog. The flaw can be leveraged remotely via the public web interface, with no requirement for privileged credentials. Once exploited, the attacker could expose sensitive files and potentially execute code, jeopardizing confidentiality, integrity, and availability of the target site.
OpenCVE Enrichment
EUVD