Impact
Improper control of filenames in PHP include/require statements allows a Local File Inclusion vulnerability in the Grevo WordPress theme, as identified by CWE‑98. This flaw can enable an attacker to load arbitrary files from the server’s file system, potentially leading to arbitrary code execution, disclosure of sensitive data, or modification of site content.
Affected Systems
WordPress sites running the themesion Grevo theme version 2.4 or earlier are affected. The vulnerability applies uniformly across all installations that use these versions of the theme.
Risk and Exploitability
The CVSS score of 8.1 indicates a high severity with high impact potential. The EPSS score of less than 1 % suggests a low probability of active exploitation, and the vulnerability is not listed in CISA’s KEV catalog. Externally, the local file inclusion can likely be triggered by a user capable of influencing the include path—for example, a site editor or an attacker who can supply a crafted request. Privileges required are not explicitly stated but may allow escalation to remote code execution if an attacker can provide a path to an executable file.
OpenCVE Enrichment