Impact
The flaw arises from insufficient validation of filenames used by the Tripgo theme in PHP include or require statements. When an attacker can supply an arbitrary filename, the theme will include that file from the server’s filesystem. This allows direct access to the contents of any file readable by the web process.
Affected Systems
All deployments of the ovatheme Tripgo WordPress theme running any version earlier than 1.5.6 are affected. No releases 1.5.6 or later contain the vulnerability.
Risk and Exploitability
The CVSS score of 8.1 indicates high severity. The EPSS score is under 1%, suggesting a low current exploitation likelihood, and the vulnerability is not listed in the CISA KEV catalog. The CVE description does not detail how the flaw is triggered, and no public exploits have been reported, so the exact attack vector and prerequisites remain unknown.
OpenCVE Enrichment