Impact
The uReach theme for WordPress contains an improper control of file names in include/require statements, allowing local file inclusion. Attackers could supply a crafted file path to read sensitive files on the server, or potentially execute arbitrary code if a writable directory is available. This vulnerability is classified as CWE‑98 and can compromise the confidentiality, integrity, and availability of the affected WordPress installation.
Affected Systems
AncoraThemes uReach theme for WordPress. All releases from the initial release up to and including version 1.3.3 are affected.
Risk and Exploitability
The severity score of 8.1 indicates a high‑risk vulnerability. The EPSS score is below 1%, suggesting there are currently few known exploits, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector requires that an attacker be able to influence the file name parameter used in the theme’s PHP code, which may be exposed through an exposed URL or form input. Despite the low exploitation probability, the high impact warrants prioritizing remediation.
OpenCVE Enrichment