Impact
Improper control of the filename used in a PHP include or require statement allows an attacker to supply an arbitrary path, resulting in a Local File Inclusion vulnerability. This flaw can enable the reading of sensitive server files or, if the included file contains executable code, the execution of arbitrary code on the system. The weakness is identified as CWE‑98.
Affected Systems
AncoraThemes Pets Land theme. All versions up through 1.2.8 are affected; no later versions are listed as vulnerable.
Risk and Exploitability
The CVSS score of 8.1 indicates a high severity vulnerability. The EPSS score is below 1 %, suggesting a low likelihood of widespread exploitation at present, and the vulnerability is not in the CISA KEV catalog. The attack vector is likely local via the theme’s file inclusion logic; an attacker who can request a specially crafted URL could trigger inclusion of arbitrary files, potentially leading to code execution or data exposure.
OpenCVE Enrichment