Impact
The vulnerability involves improper control of filenames used in PHP include/require statements, allowing local file inclusion. This flaw can enable an attacker to read arbitrary files or potentially execute code on the server, leading to unauthorized data disclosure or further compromise. The weakness is categorized as CWE‑98.
Affected Systems
Mikado‑Themes HealthFirst WordPress theme, all versions through 1.0.1 are affected. The issue applies to every installation using any of these versions.
Risk and Exploitability
The CVSS score of 8.1 classifies the flaw as high severity, while the EPSS score of less than 1% indicates a low likelihood of active exploitation at this time. It is not listed in CISA’s KEV catalog. The attack vector is inferred to be local file inclusion via unsanitized input, potentially leading to remote code execution if an attacker can control the filename or path parameters.
OpenCVE Enrichment