Impact
Unfoldwp Blogty theme contains an improper control of the filename used in a PHP include/require statement, identified as a PHP Local File Inclusion issue. An attacker who can influence the parameter that determines the included file can cause the server to read arbitrary local files. In the worst case, if the attacker can place a PHP file in a directory that is included, they could execute arbitrary code on the server, compromising confidentiality, integrity, and availability of the website.
Affected Systems
Vendors: Unfoldwp, Product: Blogty theme for WordPress. All releases from the initial release up to and including version 1.0.11 are affected. WordPress installations that use this theme are at risk until the theme is updated to a version newer than 1.0.11.
Risk and Exploitability
The CVSS score is 8.1, indicating high severity, but the EPSS score is less than 1%, suggesting low current exploitation likelihood. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a web‑based request that manipulates query or form data controlling the include path. Existing mitigation is to apply the vendor patch; until then, such requests may be blocked by a web‑application firewall configured to reject invalid include paths.
OpenCVE Enrichment
EUVD