Impact
The LuxMed WordPress theme contains an unauthenticated Local File Inclusion flaw that allows an attacker to request arbitrary files from the server’s file system. It is inferred that an attacker could read sensitive configuration files or other confidential data, but this outcome is not explicitly stated in the CVE description.
Affected Systems
The vulnerability affects ThemeREX’s LuxMed | Medicine & Healthcare Doctor WordPress Theme in all releases up to and including version 1.2.2. Hosts running these theme versions are susceptible until an updated theme is applied.
Risk and Exploitability
The CVSS score of 8.1 classifies the issue as high, indicating significant risk if left unpatched. The EPSS score is not available, so no quantitative likelihood is provided. Because the flaw is unauthenticated and relies on a public request pattern, it presents a relatively accessible attack vector for any actor with network visibility to the WordPress site. The vulnerability is not currently listed in the CISA KEV catalog.
OpenCVE Enrichment