Impact
The MaxCoach WordPress theme contains an improper control of the filename used in PHP include or require statements, enabling Local File Inclusion. If an attacker can supply a crafted path, they may read arbitrary files on the server, leading to potential extraction of sensitive data or execution of malicious code.
Affected Systems
All installations of the ThemeMove MaxCoach theme up to and including version 3.2.5 are affected.
Risk and Exploitability
The CVSS score of 8.1 indicates a high severity. The EPSS score of < 1% suggests exploitation is unlikely at present. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector involves manipulating input that controls the include path, possibly via a URL parameter or form field processed by the theme. Successful exploitation would allow an attacker to read local files and could pave the way for remote code execution if the included content is executable.
OpenCVE Enrichment