Impact
This vulnerability resides in ThemeMove EduMall theme and permits a local file inclusion due to improper control of filenames in the include/require statements. The flaw is identified as CWE‑98 and can potentially lead to disclosure of server-side files and may enable the execution of arbitrary code if the attacker can influence the included file.
Affected Systems
WordPress installations that use ThemeMove EduMall versions 4.4.7 and earlier are affected. No other vendors or products are listed as impacted by this issue.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity vulnerability. The EPSS score is less than 1%, suggesting a low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog, and based on the description, it is inferred that the attack vector is local, requiring the ability to influence the file inclusion path, typically through administrative or theme code access.
OpenCVE Enrichment