Impact
The vulnerability arises from an improper control of the filename used in PHP include/require statements within the AncoraThemes Farm Agrico WordPress theme. The flaw allows arbitrary local files to be loaded through PHP's include/require mechanism, potentially exposing the contents of files on the server.
Affected Systems
All WordPress sites that employ the AncoraThemes Farm Agrico theme version 1.3.11 or earlier are affected. The insecure include logic is present in every deployment of the theme, regardless of WordPress version or hosting environment.
Risk and Exploitability
With a CVSS score of 8.1, the flaw is classified as high severity. The EPSS score of less than 1% indicates that exploitation is currently unlikely, and the vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment