Impact
The vulnerability is an Improper Control of Filename for Include/Require Statement in PHP, allowing attackers to force the theme to include arbitrary local files. This can be used to read sensitive files or execute code if a writable file is supplied, resulting in confidentiality or integrity compromise. The weakness is identified as CWE-98.
Affected Systems
AncoraThemes Veil theme for WordPress, versions up to and including 1.9.
Risk and Exploitability
The CVSS score of 8.1 demonstrates high severity, while the EPSS score of less than 1% indicates that exploitation is unlikely, yet still possible. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is through a crafted web request that leverages the theme’s file‑include logic, which is accessible from any user with site access or from the public web surface. Successful exploitation could expose server files or allow execution of arbitrary code, compromising site confidentiality and integrity.
OpenCVE Enrichment