Impact
The AncoraThemes Hobo WordPress theme contains an improper control of filename for the include/require statement in PHP, allowing an attacker to manipulate the file path. This flaw turns the theme into a server‑side local file inclusion vector, capable of reading or executing arbitrary files on the hosting environment.
Affected Systems
Affected products are the Hobo theme from AncoraThemes, any version inferior to or equal to 1.0.10. No other product versions are listed as vulnerable, and the vulnerability spans the entire range of versions from the earliest release up to 1.0.10.
Risk and Exploitability
The CVSS score of 8.1 indicates a high severity local file inclusion risk. The EPSS score of less than 1% suggests a very low probability of current exploitation, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker might craft a web request to exploit the theme’s include implementations, allowing the inclusion of local files, which could lead to sensitive data disclosure or code execution if PHP files are read and then executed.
OpenCVE Enrichment