Impact
Improper control of filenames in include/require statements allows an attacker to reference arbitrary local files within the Vango WordPress theme. This flaw can lead to disclosure of sensitive data or execution of unintended code, compromising confidentiality or integrity. The vulnerability is formally identified as CWE‑98.
Affected Systems
The Vango theme for WordPress, distributed by goalthemes, is affected in all releases up to and including version 1.3.3. No later version is reported as vulnerable.
Risk and Exploitability
The CVSS score of 8.1 places this issue in the high severity range, while the EPSS score of less than 1 % indicates that successful exploitation is currently very unlikely. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the likely attack vector involves an HTTP request containing a crafted parameter that manipulates the file path used in a PHP include or require; this vector requires application‑level input to be abused.
OpenCVE Enrichment