Impact
The Hope theme for WordPress suffers from an improper control of the filename used in the PHP include/require statement, allowing local files to be included without proper validation. This flaw corresponds to CWE‑98 and can enable attackers to read sensitive files or execute arbitrary PHP code if the included file contains malicious content.
Affected Systems
The vulnerability affects all releases of the ThemeREX Hope charity‑is‑hope theme up to and including version 3.0.0. Any WordPress installation using those theme versions is at risk.
Risk and Exploitability
With a CVSS score of 8.1, the flaw is considered high severity. The EPSS score of less than 1 % indicates a low likelihood of exploitation at this time, and it is not listed in the CISA KEV catalog. The attack would typically require an attacker who can influence an input that determines the file path or who can read arbitrary files on the server, potentially leading to code execution or disclosure of confidential data.
OpenCVE Enrichment