Impact
The Rashy theme for WordPress contains an improper control of filename for include/require statements in PHP, enabling a local file inclusion flaw. An attacker who can influence the include path can cause the server to read arbitrary files or execute local PHP scripts, potentially leading to disclosure of confidential data or server compromise. This vulnerability is classed as CWE‑98 and represents a severe breach of confidentiality and integrity for the affected site.
Affected Systems
WordPress sites that use the Rashy theme from goalthemes, specifically all releases up through version 1.1.3. Versions prior to the first release are not known to be affected, but any instance of the theme before the release of the fix is vulnerable.
Risk and Exploitability
The CVSS score of 8.1 indicates high severity, while the EPSS score of less than 1% suggests a very low probability of current exploitation. The vulnerability is not included in CISA’s KEV catalog, implying no known high‑profile exploitation currently. Because the flaw requires manipulation of an include path, the attack vector is most likely local or through a crafted request that can be made by a user or malicious script. In the absence of public exploitation evidence, the overall risk remains high due to the serious potential impact if the flaw is exploited within a browser session or via an authenticated path.
OpenCVE Enrichment