Impact
A path traversal flaw allows an attacker to include local files within the Mikado-Themes MediClinic WordPress theme by crafting a URL that contains repeating slash sequences. The vulnerability can lead to execution of arbitrary PHP code, revealing sensitive information or enabling further compromise. The weakness is identified as CWE-35, indicating improper handling of file paths.
Affected Systems
WordPress sites using the MediClinic theme from any version through 2.1 are affected. The theme is distributed by Mikado-Themes under the qodeinteractive:mediclinic WordPress package.
Risk and Exploitability
The CVSS score of 8.1 signals a high severity and the EPSS score of less than 1% suggests that exploitation frequency is currently low, though the vulnerability remains viable. The absence from the CISA KEV list means it has not yet been publicly exploited at scale, but the potential for remote code execution warrants proactive remediation. Attackers could trigger the flaw by sending a specially crafted request to the affected theme’s PHP endpoint, thereby including arbitrary files from the server’s filesystem.
OpenCVE Enrichment
EUVD