Impact
An issue in the Favethemes Houzez Theme – Functionality plugin allows an attacker to control the filename supplied to PHP's include or require statements. This improper input validation can result in the plugin reading or executing an arbitrary local file, and if the server permits it, the attacker may also cause remote code execution. The flaw is related to CWE‑98 and can lead to disclosure of sensitive information or compromise of the site's integrity.
Affected Systems
The vulnerability applies to any installation of the Favethemes Houzez Theme – Functionality plugin with a version number n/a through 4.1.8. WordPress sites that have not upgraded past 4.1.8 are therefore potentially affected by this flaw.
Risk and Exploitability
The CVSS v3 base score of 7.5 indicates high severity. The EPSS score of less than 1% suggests the likelihood of exploitation is currently low, though a zero‑day would still pose a high risk. The flaw is not listed in CISA's KEV catalog. The likely attack vector is via user‑controlled input that influences the include/require path; no special privileges beyond normal web access appear to be required for exploitation.
OpenCVE Enrichment