Impact
The flaw is an improper control of filenames in PHP include/require statements, allowing the application to include arbitrary files on the local filesystem and potentially execute code. This weakness is classified as CWE-98 – Improper Control of Filename for Include/Require.
Affected Systems
WordPress installations that use AncoraThemes Hanani version 1.2.11 or earlier are affected; the issue covers all releases from the first available version up through 1.2.11.
Risk and Exploitability
The CVSS score of 8.1 indicates high severity, while the EPSS score of less than 1 % suggests exploitation is currently unlikely. The vulnerability is not listed in the CISA KEV catalog. Attackers would most likely exploit the flaw by sending crafted web requests that manipulate the include path; no public exploit has been reported, so the risk hinges on manual exploitation attempts.
OpenCVE Enrichment