Impact
The SevenTrees WordPress theme contains an improper validation of file names used in PHP include or require calls, allowing an attacker to provide arbitrary paths. This flaw is identified as CWE‑98 and is scored 8.1 on the CVSS v3 baseline. The vulnerability allows PHP local file inclusion, which can reveal sensitive data on the server or interfere with the normal operation of the website.
Affected Systems
Users of the axiomthemes SevenTrees theme version 1.0.2 or earlier are affected. The issue appears across all WordPress installations that activate this theme.
Risk and Exploitability
The EPSS score is below 1 % and the vulnerability is not listed in the CISA KEV catalog, indicating a low current exploitation likelihood. Nevertheless, the high CVSS rating signals that, if an attacker can successfully manipulate the file path, the resulting local file inclusion can compromise confidentiality, integrity, and availability of the web application.
OpenCVE Enrichment