Impact
The vulnerability is an improper control of the filename used in a PHP include/require statement, leading to a local file inclusion flaw in the AncoraThemes Prider WordPress theme. An attacker who can influence the filename can read arbitrary files on the server or trigger execution of server‑side scripts, potentially resulting in full compromise of the affected WordPress installation.
Affected Systems
AncoraThemes Prider theme versions up to and including 1.1.3.1 are impacted. Any WordPress site using these or older releases of the theme is at risk until the fixed version is deployed.
Risk and Exploitability
The CVSS score of 8.1 classifies this as High severity. The EPSS score of less than 1% indicates a low exploit probability at present, and the vulnerability is not listed in the CISA KEV catalog. The most likely attack vector involves an attacker crafting a request that manipulates the filename parameter within the theme’s inclusion logic; the flaw is exploitable without prior authentication, suggesting potential for unauthenticated or low‑privilege access. The lack of an official workaround means remediation must rely on updating the theme or otherwise blocking inclusion of arbitrary files.
OpenCVE Enrichment