Impact
The issue arises from an improper control of filename for include/require in the PHP code of the Billey theme, allowing a local file inclusion vulnerability. An attacker who can manipulate the include path may read arbitrary files on the server or, in some configurations, execute code, thereby compromising the confidentiality, integrity, and potentially the availability of the WordPress site.
Affected Systems
Any installation of the ThemeMove Billey WordPress theme whose version is less than 2.1.6 is affected. The vulnerability exists in all earlier releases of the theme running on WordPress platforms where the vulnerable code resides.
Risk and Exploitability
With a CVSS score of 8.1 the flaw is considered severe, but its EPSS score is below 1%, indicating a low likelihood of active exploitation at present. The vulnerability is not listed in CISA’s KEV catalog. The attack vector is most likely local, triggered by a crafted URL or theme configuration that exposes the dangerous include call; this inference is drawn from the nature of the flaw.
OpenCVE Enrichment