Impact
An unauthenticated Local File Inclusion flaw (CWE‑98) exists in the AncoraThemes Lighthouse theme through version 1.2.12. This vulnerability permits an attacker to include local files on the server via the theme’s inclusion logic.
Affected Systems
Any WordPress site that uses the AncoraThemes Lighthouse theme version 1.2.12 or earlier is affected. Sites running newer releases are expected to be unaffected.
Risk and Exploitability
The CVSS score of 8.1 indicates high severity. The EPSS score is less than 1 %, showing a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be a web request that does not require authentication.
OpenCVE Enrichment