Impact
The vulnerability arises from improper validation of filenames used in PHP include or require statements within the AncoraThemes W&D theme. Attackers can manipulate the filename parameter in a web request to include arbitrary local files, leading to disclosure of sensitive data and potentially execution of malicious code. This flaw corresponds to CWE‑98, a Local File Inclusion weakness.
Affected Systems
The affected product is the AncoraThemes W&D WordPress theme, versions from the initial release up to and including 1.0. Older or newer releases are not affected according to the CNA data.
Risk and Exploitability
The CVSS score of 8.1 indicates high severity. The EPSS score is below 1 % suggesting a low probability of exploitation in the near term, and the vulnerability is not listed in the CISA KEV catalog. Attackers can exploit the flaw remotely by sending a crafted request containing a controlled filename; the impact is restricted to the local server environment unless the LFI can be leveraged further to inject exploitable code.
OpenCVE Enrichment