Impact
The vulnerability is an improper control of filename for include/require statements in PHP, allowing local file inclusion in the WordPress Blueprint theme. This flaw, classified as CWE-98, can enable an attacker to read arbitrary files on the server and, in some configurations, may lead to remote code execution if the attacker can supply or manipulate file paths used in includes.
Affected Systems
Affected systems are installations of the Code Supply Co. Blueprint theme for WordPress running any version prior to 1.1.5. Administrators should verify that the theme version in use is earlier than 1.1.5, as all earlier releases contain the LFI flaw.
Risk and Exploitability
The CVSS base score of 8.1 indicates a high severity impact. The EPSS score is not available, and the vulnerability is not listed in CISA's KEV catalog. Because the flaw permits inclusion of arbitrary local files, exploitation is likely to be feasible if web‑application or server misconfigurations allow user‑controlled parameters to influence include paths. The risk remains high until the theme is upgraded.
OpenCVE Enrichment