Impact
AncoraThemes Inset theme contains an improper control of filename for include/require statements, allowing a PHP Local File Inclusion flaw. The vulnerability enables an attacker to specify arbitrary local file paths that are included by the theme, potentially exposing sensitive data or executing malicious code. This flaw is classified as CWE-98 and can undermine confidentiality, integrity and potentially availability of the affected WordPress site.
Affected Systems
AncoraThemes Inset, WordPress theme version 1.18.0 and earlier. No additional version details are available; the issue affects all releases through and including v1.18.0.
Risk and Exploitability
The CVSS score of 8.1 indicates high severity, while the EPSS score of less than 1% suggests a low probability of exploitation at the time of analysis. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is a Local File Inclusion available through the theme’s include mechanism, which would typically require the attacker to have the ability to influence the filename argument, possibly via authenticated access or an exploited file upload functionality. No exploitation proof is documented in the provided data.
OpenCVE Enrichment