Impact
The vulnerability permits an attacker to delete arbitrary files on the server by crafting a path traversal payload in the AivahThemes Hostme v2 theme. This flaw can lead to the removal of critical WordPress files, loss of content, and overall site downtime, representing a significant integrity violation with potential availability impact.
Affected Systems
WordPress installations using the AivahThemes Hostme v2 theme, versions from the initial release through 7.0, are affected. Any site running a vulnerable theme version can be exploited.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity, but the EPSS score of less than 1% suggests a low likelihood of exploitation at present. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector is remote via an HTTP request that triggers the theme's path handling logic.
OpenCVE Enrichment