Impact
The CityGov theme for WordPress contains a flaw in filename handling for PHP include/require statements, permitting an attacker to specify arbitrary local paths and trigger inclusion of files with PHP execution privileges. This vulnerability, identified as CWE‑98, can lead to disclosure of sensitive files or the execution of arbitrary code on the web server.
Affected Systems
AncoraThemes CityGov WordPress theme, versions 1.9 and earlier. The issue exists across all builds from the first release through version 1.9.
Risk and Exploitability
The CVSS score of 8.1 classifies this flaw as high severity. With an EPSS less than 1%, exploitation is considered unlikely under current public data. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is a remote HTTP request that supplies a crafted request parameter or URL to trigger the vulnerable include logic, requiring the WordPress site to be publicly reachable and the theme to be active.
OpenCVE Enrichment
EUVD