Impact
LoftOcean CozyStay theme contains an improper control of filename for the include/require statement that allows local file inclusion through PHP. This flaw, classified as CWE‑98, lets an attacker supply a crafted path to read arbitrary files on the server and potentially execute attacker‑supplied code. If the included file contains malicious PHP, the vulnerability could be escalated to remote code execution, compromising confidentiality, integrity, and availability.
Affected Systems
All installations of the CozyStay theme by LoftOcean running a version earlier than 1.9.1 are affected. The vulnerability applies to every deployment where the theme is enabled; the affected range is from the earliest released version up to but not including 1.9.1.
Risk and Exploitability
The CVSS score of 8.1 indicates high severity, but the EPSS score of less than 1% suggests a low likelihood of exploitation in the wild. The vulnerability is not cataloged in the CISA KEV list. An attacker would need to target a site with the vulnerable theme and supply a malicious path to trigger the inclusion. The low EPSS does not eliminate the risk, especially for high‑value targets, so applying a patch promptly reduces both the attack surface and potential impact.
OpenCVE Enrichment