Impact
The vulnerability exists in AncoraThemes Tails theme for WordPress and allows an attacker to supply a controlled filename to a PHP include/require statement. This improper filename control leads to local file inclusion, permitting the execution of malicious code or the disclosure of sensitive files on the hosting server. The weakness is classified as CWE-98 and can compromise confidentiality, integrity, and availability of the affected web application.
Affected Systems
Any WordPress site that has installed AncoraThemes Tails theme version 1.4.12 or earlier is impacted. This includes all releases from the earliest version up to and including 1.4.12.
Risk and Exploitability
The base score of 8.1 indicates a high severity issue, but the EPSS score of less than 1% suggests a low probability of exploitation at present. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires an attacker to supply a path to a local file that the PHP process can read, which can typically be performed without authentication via public inputs or administrative interfaces that accept file names. Given the lack of in‑market exploits yet, the overall risk remains moderate to high, with potential for significant privilege escalation if only site‑level credentials are available.
OpenCVE Enrichment