Impact
The vulnerability is a path traversal flaw that permits PHP local file inclusion within the Mikado-Themes Grill and Chow WordPress theme. It is classified as CWE‑35 and allows an attacker to request the theme to include arbitrary files from the server, potentially exposing sensitive files or code base when the theme attempts to process them.
Affected Systems
WordPress installations that use the Mikado‑Themes Grill and Chow theme version 1.6 or earlier are affected.
Risk and Exploitability
The CVSS score of 8.1 signifies a high severity, yet the EPSS score of less than 1% indicates that exploitation is currently unlikely. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is a specially crafted URL or input that uses the theme’s file inclusion mechanism to traverse outside its intended directory.
OpenCVE Enrichment
EUVD