Impact
Unauthenticated Local File Inclusion has been discovered in the Pearl - Corporate Business WordPress theme versions 3.4.10 and earlier. A visitor can supply a crafted file path that bypasses the theme’s validation logic, causing the server to read an arbitrary file from the local filesystem. This flaw, classified as CWE-98, can expose configuration files, database credentials, or other sensitive data that resides on the server.
Affected Systems
The vulnerability affects the Pearl - Corporate Business theme distributed by StylemixThemes. Any WordPress installation that has version 3.4.10 or lower of this theme deployed is affected.
Risk and Exploitability
The flaw carries a CVSS score of 8.1, indicating high severity. The EPSS score of <1% denotes a low estimated likelihood of exploitation in the wild. Based the description, it is inferred that a remote visitor can send a request with a crafted file path to trigger the inclusion, making the attack straightforward for malicious actors. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires only that the vulnerable theme be present and that an attacker be able to send a request containing the crafted path, making defense a priority if the theme is installed.
OpenCVE Enrichment