Impact
The vulnerability is an improper control of filename for include/require statements in the Mikado‑Themes Verdure WordPress theme, allowing a Local File Inclusion. An attacker can supply a crafted request to the theme to include arbitrary local files, potentially reading sensitive information or executing code if the included file is PHP. The weakness is classified as CWE‑98 and can be leveraged to compromise site confidentiality, integrity, and possibly availability.
Affected Systems
Mikado‑Themes Verdure theme for WordPress, versions 1.6 and earlier.
Risk and Exploitability
The CVSS score is 8.1, indicating high severity. The EPSS score is less than 1 %, suggesting that exploitation likelihood is currently low. The vulnerability is not listed in the CISA KEV catalog. It is inferred that the attack vector requires access to the theme’s PHP files via a web request, making online attackers the most likely exploitants.
OpenCVE Enrichment