Impact
The vulnerability is an improper control of filename for include or require statements in a PHP application, classified as a PHP Local File Inclusion flaw (CWE-98). An attacker could potentially trigger the inclusion of arbitrary local files through the ThemeREX Alliance theme, allowing the reading of sensitive configuration data and possibly enabling further exploitation. The impact is the exposure of confidential files and the risk of escalating to remote code execution if malicious files are introduced.
Affected Systems
This flaw affects the ThemeREX Alliance WordPress theme, including all releases up to and including version 3.1.1. The affected system is WordPress installations that have this theme active.
Risk and Exploitability
The CVSS score of 8.1 indicates high severity. The EPSS score of less than 1% suggests exploitation probability is currently low, and the vulnerability is not listed in the CISA KEV catalog. The likely attack requires a local attacker or a user that can influence a file path parameter that is processed by the theme. Successful exploitation would grant file disclosure and could lead to further compromise if local files are used to inject malicious code.
OpenCVE Enrichment