Impact
Axiomthemes Aromatica theme contains an improper handling of filenames in PHP include/require statements. This flaw allows a local file inclusion vulnerability that can grant an attacker the ability to read arbitrary files on the server and, in some cases, execute code. The CVSS score of 8.1 indicates a high severity due to the potential impact on confidentiality, integrity, and availability.
Affected Systems
The vulnerability affects the Aromatica WordPress theme provided by Axiomthemes. All releases from the first available version through version 1.8 are impacted; newer releases (above 1.8) are not affected.
Risk and Exploitability
The EPSS score is less than 1%. The vulnerability is not listed in the CISA KEV catalog. Attackers would need access to the web application and could exploit the flaw via crafted input passing a file path to the include function. The ease of exploitation is moderate to high because no additional credentials are required beyond access to the theme’s settings or front‑end entry points. Given the high CVSS score, the risk remains significant for unpatched installations.
OpenCVE Enrichment