Impact
The flaw enables an attacker to read arbitrary files from the server by manipulating the filename used in a PHP include statement. Using an LFI approach, a malicious user could access logs, configuration files, or other sensitive data, providing a foothold for further exploitation such as code execution or privilege escalation.
Affected Systems
WordPress installations that use the Calafate theme version 1.7.7 or earlier are vulnerable. Any site still running those theme versions remains susceptible.
Risk and Exploitability
The CVSS score of 7.5 indicates a high potential impact, yet the EPSS score below 1% suggests the probability of exploitation is currently low. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker could leverage the LFI flaw by manipulating the file name used in the theme’s PHP include statement, but the exact attack vector is not detailed in the provided data.
OpenCVE Enrichment