Impact
The vulnerability is an improper control of filenames in PHP include/require statements, identified as a PHP Remote File Inclusion flaw. This allows an attacker to specify arbitrary file paths, which can expose sensitive data or enable execution of arbitrary code on the server. The weakness corresponds to CWE-98.
Affected Systems
All installations of the Elated‑Themes Savory WordPress theme at version 2.5 or earlier are affected. No specific patch version is provided in the CVE data, so any deployment using an outdated theme is vulnerable until an update beyond 2.5 is applied.
Risk and Exploitability
The CVSS score of 8.1 classifies the flaw as high severity, and the EPSS value of less than 1% suggests a low but non‑zero likelihood of exploitation. The vulnerability is web‑based and can be triggered through normal user requests to the site; the lack of an official KEV listing indicates no known widespread exploitation at the time of this analysis.
OpenCVE Enrichment