Impact
AncoraThemes OnLeash theme contains an improper control of filename when executing PHP include/require statements. Identified as CWE-98, this flaw allows local file inclusion via PHP. An actor may supply a crafted filename, enabling read access to local files or execution of PHP code if the web server has the necessary permissions.
Affected Systems
All installations of the WordPress OnLeash theme from the earliest release up through version 1.5.2 are affected. Versions 1.5.3 and later have the fix and are not vulnerable.
Risk and Exploitability
The CVSS score of 8.1 signals high severity; the EPSS score of less than 1% indicates a low probability of exploitation in the current landscape. The vulnerability is not listed in CISA KEV. Based on the description, it is inferred that the attack vector involves an attacker supplying a crafted filename via the theme’s interface to trigger the include, potentially revealing sensitive files or executing code.
OpenCVE Enrichment