Impact
The AncoraThemes Indoor Plants WordPress theme implements include/require operations using a filename supplied without proper validation, allowing a local file inclusion vulnerability. This allows an attacker to read or execute arbitrary files from the server, which may lead to full code execution and compromise of the site. The weakness corresponds to CWE-98.
Affected Systems
WordPress plugins and themes, specifically the Indoor Plants theme by AncoraThemes, version 1.2.7 and earlier are affected. Any WordPress installation that has this theme active and unpatched is vulnerable.
Risk and Exploitability
The vulnerability carries a CVSS score of 8.1, indicating high severity. The EPSS score of less than 1% shows that exploit activity is currently rare, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector involves manipulating URL parameters or form inputs that influence the include path, enabling a remote attacker to trigger local file inclusion if the theme does not sanitize the input.
OpenCVE Enrichment