Description
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Consultor | Consulting, Accounting & Legal Counsel WordPress Theme consultor allows PHP Local File Inclusion.This issue affects Consultor | Consulting, Accounting & Legal Counsel WordPress Theme: from n/a through <= 1.2.4.
Published: 2026-03-05
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Local File Inclusion
Action: Patch Now
AI Analysis

Impact

AncoraThemes Consultor WordPress Theme contains an improper control of filename for include/require statements in its PHP code, creating a local file inclusion vulnerability (CWE‑98). An attacker can trick the application into including and potentially executing arbitrary local files, which may expose sensitive configuration data or allow the execution of malicious code. The flaw directly compromises confidentiality and could lead to integrity violations if attacker‑controlled files are loaded.

Affected Systems

The vulnerability is present in AncoraThemes Consultor | Consulting, Accounting & Legal Counsel WordPress Theme versions up to and including 1.2.4. Any installation of the theme identified as Consultor that has not been updated beyond version 1.2.4 is impacted.

Risk and Exploitability

Based on the description the likely attack vector is the supply of a crafted input that directs the application to include a local file; this can be triggered via a URL or form parameter. The vulnerability has a high severity with a CVSS score of 8.1 while its EPSS score is below 1%, indicating a low current exploitation likelihood. It is not listed in the CISA KEV catalog. If an attacker can cause the application to execute code from the included file, they may gain elevated privileges or further compromise the site. The main risk lies in unauthorized access to sensitive files and the potential for code execution, which can affect confidentiality, integrity, and availability of the WordPress instance.

Generated by OpenCVE AI on April 17, 2026 at 12:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest consultor theme update from AncoraThemes to eliminate the vulnerable include/require handling.
  • If upgrading now is not possible, restrict PHP include paths or set include_path to a trusted directory and implement file‑permission checks to ensure only expected files are included.
  • As a temporary measure, remove or replace the vulnerable dynamic include/require calls with hardcoded, safe file names to prevent any user‑supplied input from being processed.

Generated by OpenCVE AI on April 17, 2026 at 12:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 09 Mar 2026 18:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 06 Mar 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Ancorathemes
Ancorathemes consultor | Consulting, Accounting & Legal Counsel Wordpress Theme
Wordpress
Wordpress wordpress
Vendors & Products Ancorathemes
Ancorathemes consultor | Consulting, Accounting & Legal Counsel Wordpress Theme
Wordpress
Wordpress wordpress

Thu, 05 Mar 2026 06:15:00 +0000

Type Values Removed Values Added
Description Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Consultor | Consulting, Accounting & Legal Counsel WordPress Theme consultor allows PHP Local File Inclusion.This issue affects Consultor | Consulting, Accounting & Legal Counsel WordPress Theme: from n/a through <= 1.2.4.
Title WordPress Consultor | Consulting, Accounting & Legal Counsel WordPress Theme theme <= 1.2.4 - Local File Inclusion vulnerability
Weaknesses CWE-98
References

Subscriptions

Ancorathemes Consultor | Consulting, Accounting & Legal Counsel Wordpress Theme
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-01T14:15:08.049Z

Reserved: 2026-02-19T09:51:35.296Z

Link: CVE-2026-27336

cve-icon Vulnrichment

Updated: 2026-03-09T17:35:37.999Z

cve-icon NVD

Status : Deferred

Published: 2026-03-05T06:16:24.110

Modified: 2026-04-22T21:26:58.303

Link: CVE-2026-27336

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-17T13:00:12Z

Weaknesses