Impact
This vulnerability arises from Improper Control of Filename for Include/Require Statement in PHP, allowing an attacker to arbitrarily include local files via the VideoPro WordPress theme. By supplying a crafted path to the theme’s include/require logic, an adversary can read any readable file on the server, such as configuration files or credentials. The flaw is identified as CWE‑98: Improper Control of File Name for Include/Require Statement.
Affected Systems
Any WordPress installation running CactusThemes VideoPro version 2.3.8.1 or earlier is affected. The flaw applies from the earliest available release through 2.3.8.1.
Risk and Exploitability
The CVSS base score of 8.1 signals a high severity issue. The EPSS score is 0.0005 (< 1%), and the vulnerability is not listed in the CISA KEV catalog, indicating no known public exploits at this time. The likely attack vector is remote, via a crafted URL or form input that targets the theme’s include logic. Successful exploitation would allow reading arbitrary files on the server, leading to significant information disclosure and possibly facilitating further compromise.
OpenCVE Enrichment