Impact
A flaw in the North WordPress theme’s include/require logic lets an attacker specify arbitrary filenames for PHP inclusion. This improper control can reveal sensitive local files or enable execution of malicious code, compromising confidentiality, integrity, and availability of the affected site.
Affected Systems
The North theme for WordPress, supplied by fuelthemes, is affected in all releases from the initial version through version 5.7.5 inclusive. Any site running this theme within that range is vulnerable.
Risk and Exploitability
The CVSS score of 8.1 marks the vulnerability as high severity, but the EPSS score of less than 1% indicates a low probability of current exploitation. The issue is not listed in the CISA KEV catalog. Exploitation would likely occur via a local or web‑based attack using a crafted request that triggers the vulnerable include logic.
OpenCVE Enrichment