Impact
The vulnerability is an improper control of the filename used in a PHP include/require statement, allowing an attacker to cause the application to include local files. This flaw directly compromises confidentiality and could provide a pathway to more serious attacks if an included file is a system or configuration file.
Affected Systems
WordPress sites using the AncoraThemes DJ Rainflow theme version 1.3.13 or earlier are affected. The theme is distributed through AncoraThemes and is commonly installed on WordPress installations.
Risk and Exploitability
The CVSS score of 8.1 indicates high severity, while the EPSS score of less than 1% suggests a low contemporary exploitation probability; the vulnerability is not listed in CISA’s KEV catalog. Exploitation requires the attacker to supply a crafted filename. The likely attack vector is via HTTP requests that reach the theme's file inclusion logic; it is inferred that authentication may not be required depending on how the theme is used.
OpenCVE Enrichment