Impact
The vulnerability arises from Improper Control of Filename for Include/Require Statement in the Kossy theme, which permits a Local File Inclusion flaw. An attacker who can influence the filename parameter can cause the server to read and execute a local file. This flaw corresponds to CWE‑98 and can allow the attacker to read sensitive files or execute arbitrary PHP code if a suitable file is provided.
Affected Systems
ApusWP’s Kossy – Minimalist eCommerce WordPress Theme, all releases up through version 1.45, is affected. No additional vendors or products are listed as impacted.
Risk and Exploitability
The CVSS score of 8.1 indicates a high‑severity vulnerability. The EPSS score of less than 1 % reflects a low likelihood of exploitation at present. The flaw is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is a web request that manipulates the include statement; an attacker does not need elevated privileges to exploit the vulnerability, but the impact may involve exposure of local files or execution of malicious PHP code.
OpenCVE Enrichment
EUVD