Impact
The vulnerability allows an attacker to supply a crafted filename to an include/require statement, resulting in local file inclusion. This can lead to arbitrary code execution and expose sensitive site data. The root weakness is improper control of filenames in PHP.
Affected Systems
CocoBasic’s Anotte theme for WordPress, versions 1.8 and earlier, is affected. No specific patched version is mentioned, so any release up to 1.8 remains vulnerable.
Risk and Exploitability
The CVSS score of 8.1 indicates high severity. The EPSS score is under 1%, indicating low current exploitation probability, and the issue is not listed in the KEV catalog. The attack vector is inferred to be a web‑based request that supplies a malicious filename to trigger the vulnerable include/require behavior.
OpenCVE Enrichment
EUVD