Impact
An unauthenticated Local File Inclusion flaw (CWE‑98) exists in the AncoraThemes Lighthouse theme up to version 1.2.12. The flaw allows an external actor to trigger the theme’s file inclusion logic without needing authentication. Based on the nature of the flaw, it is inferred that an attacker could request the server to read and potentially disclose arbitrary local files, compromising confidentiality and integrity of the WordPress installation.
Affected Systems
Any WordPress site that relies on the AncoraThemes Lighthouse theme version 1.2.12 or earlier is vulnerable. Hosts using newer releases beyond 1.2.12 are believed to be unaffected. The vulnerability applies to all environments where the theme is installed and called, regardless of site role or user level. The vulnerability is not listed in the CISA KEV catalog.
Risk and Exploitability
The CVSS score of 8.1 indicates high severity. The EP a very low but non‑zero is not listed in the CISA KEV catalog. It is inferred that an attacker could craft a web request that triggers the theme’s inclusion mechanism to read local files, and that exploitation would be possible from any external host that can reach the WordPress server. The attack vector is likely network (web), and the vulnerability remains unauthenticated, meaning no privileged credentials are required.
OpenCVE Enrichment