Impact
This vulnerability allows the inclusion of local files through an improperly controlled filename in the Faith & Hope theme, potentially exposing sensitive data and enabling attackers to read arbitrary files on the server. The weakness is a classic Local File Inclusion flaw, classified as CWE-98, which can be exploited if input validation is inadequate.
Affected Systems
AncoraThemes "Faith & Hope" theme, versions up to and including 2.13.0 are affected.
Risk and Exploitability
The CVSS base score for this issue is 8.1, indicating high severity. The EPSS score is below 1%, suggesting that, at present, the probability of exploitation is low, and the vulnerability is not listed in the CISA KEV catalog. Likely exploitation requires an attacker to influence the file path used by the application, such as through a crafted request or user input.
OpenCVE Enrichment