Impact
The AncoraThemes Strux theme contains an improper control of the filename used in PHP include/require statements, a classic file inclusion flaw (CWE-98). This vulnerability allows an attacker to specify a path that the application will include, potentially exposing sensitive files or executing arbitrary code. The impact ranges from information disclosure to full remote code execution depending on the file system layout and server permissions, and can affect the entire WordPress site hosting the theme.
Affected Systems
WordPress sites that are using AncoraThemes Strux theme version 1.9 or earlier are impacted. Any site deploying the theme from the earliest releases up to version 1.9 is vulnerable, regardless of the WordPress core version.
Risk and Exploitability
The CVSS score of 8.1 indicates high severity. With an EPSS score of less than 1 % the current probability of exploitation is very low, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector involves a web‐based request to a site using the theme, where the attacker supplies a malicious parameter that controls the include path. If an attacker succeeds, they could read arbitrary files from the server or execute code, leading to compromise of the entire WordPress installation.
OpenCVE Enrichment