Impact
AncoraThemes Femme theme contains a flaw that allows an attacker to supply an arbitrary filename to a PHP include or require statement. This improper control of the filename can be leveraged to read local files on the WordPress installation. The vulnerability is classified as a Local File Inclusion (CWE‑98).
Affected Systems
WordPress sites that use the AncoraThemes Femme theme version 1.3.11 or earlier are impacted. The vulnerability applies to all releases from the first available version up through 1.3.11.
Risk and Exploitability
The vulnerability scores a CVSS of 8.1 indicating high severity, while the EPSS score of less than 1% suggests a low likelihood of exploitation in the wild at this time. It is not listed in the CISA KEV catalog. Attackers can exploit the flaw by manipulating a request that includes a controllable file parameter, which is part of the theme’s functionality. The likely attack vector is over the web interface, requiring access to the WordPress administration area or any URL that triggers the vulnerable include logic.
OpenCVE Enrichment