Impact
The vulnerability is a path traversal flaw that enables PHP Local File Inclusion in the Creanncy Davenport - Versatile Blog and Magazine WordPress Theme. By exploiting the flaw a remote attacker can include arbitrary files from the server, potentially revealing sensitive configuration data or executing code if the included file contains PHP. This weakness is classified as CWE‑35.
Affected Systems
All installations of the Creanncy Davenport WordPress Theme up through version 1.3 are impacted. The affected product is the Davenport – Versatile Blog and Magazine WordPress Theme, with the vulnerable range noted as from n/a to <= 1.3.
Risk and Exploitability
The CVSS score of 8.1 indicates high severity, while the EPSS score of < 1% suggests the probability of exploitation is low at present. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is remote, through a crafted URL that exploits the path traversal in the theme’s file inclusion logic.
OpenCVE Enrichment
EUVD