Impact
A path traversal flaw in the Katerio - Magazine WordPress theme permits local file inclusion; the vulnerability can enable an attacker to read arbitrary files on the server and potentially execute code, thereby compromising confidentiality, integrity, and availability of the website.
Affected Systems
The issue affects the Katerio - Magazine theme from the earliest releases through version 1.5.1, supplied by TMRW‑studio.
Risk and Exploitability
The CVSS score of 8.1 reflects significant risk, and although the EPSS score is below 1%, exploitation is still plausible because the vulnerability is a local file inclusion that can be triggered by crafted HTTP requests. The CVE is not listed in CISA's KEV catalog. Attackers can exploit this weakness by supplying a malicious file path to the vulnerable theme code, then reading sensitive files or executing arbitrary PHP code if the server environment permits.
OpenCVE Enrichment
EUVD