Impact
The vulnerability in the Indutri theme permits an attacker to include local PHP files through improper handling of filenames, which could expose sensitive file contents or potentially execute unintended code when crafted inputs are provided.
Affected Systems
WordPress installations using the Gavias Indutri theme, specifically versions earlier than 1.3.0; all releases affected from the earliest version up to, but not including, 1.3.0.
Risk and Exploitability
The CVSS score of 8.1 indicates high impact, while the EPSS score of less than 1% shows a low likelihood of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector involves supplying a crafted filename through a web request parameter that is passed to include or require statements within the theme.
OpenCVE Enrichment