Impact
The vulnerability arises from improper control of filenames used in PHP include/require statements in the Mikado‑Themes Cocco WordPress theme, which allows locally included files. An attacker can manipulate input that is passed to these statements, causing the server to read or execute arbitrary local files, potentially leading to information disclosure or code execution if the included content is executable.
Affected Systems
Affected systems are all releases of the Mikado‑Themes Cocco WordPress theme from the earliest available version through 2.0.
Risk and Exploitability
The CVSS base score of 8.1 indicates high severity, while the EPSS score of less than 1 % suggests a very low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Attackers would target the theme via crafted requests that trigger the vulnerable include, potentially leveraging administrative or public access to the theme’s parameters. Inferred attack vector is local file inclusion through manipulated parameters or tampered file paths; further exploitation could achieve code execution if the attacker controls the local files included.
OpenCVE Enrichment