Impact
This vulnerability is an instance of CWE-98, where the Neptunus theme’s include mechanism does not properly validate the filename, enabling an attacker to include arbitrary local files via crafted requests. This can allow the attacker to read sensitive files or, if a PHP file can be supplied, potentially execute code, thereby compromising the confidentiality and integrity of the site.
Affected Systems
The Neptunus theme by axiomthemes, any installation running version 1.0.11 or older, is affected.
Risk and Exploitability
The CVSS score of 8.1 indicates a high severity. The EPSS score is below 1%, suggesting a low probability of exploitation in the wild at this time. The vulnerability is not listed in CISA's KEV catalog. The likely attack vector is a local request to the theme’s PHP files with a malicious path, requiring access to the site’s URL and possibly an authenticated user. Exploitation would be easier in environments where the theme files are writable or where the server runs with elevated privileges.
OpenCVE Enrichment