Impact
The vulnerability is an improper control of filename for an include/require statement in PHP, leading to local file inclusion in the Fribbo theme. This flaw allows an attacker to specify a path to include arbitrary local files or potentially execute code, compromising the confidentiality, integrity, or availability of the underlying web application. The weakness is classified as CWE‑98.
Affected Systems
AncoraThemes Fribbo theme for WordPress, versions up to and including 1.1.0, is impacted. Any WordPress site running that theme installation is vulnerable.
Risk and Exploitability
The CVSS score of 8.1 indicates high severity, while the EPSS score of less than 1% suggests a low probability of exploitation at present. Because the flaw involves local file inclusion, the attack likely requires some form of authenticated or local access, but if the theme processes user‑supplied input, remote exploitation might be possible. The vulnerability is not listed in CISA’s KEV catalog, so no known active exploitation has been reported. However, the high impact warrants prompt mitigation.
OpenCVE Enrichment