Impact
The vulnerability is an unauthenticated local file inclusion flaw in the Elated‑Themes Audrey theme for WordPress version 1.5 or earlier. Through the theme’s code, an attacker can request arbitrary files on the server, which is a classic local file inclusion weakness classified as CWE‑98.
Affected Systems
WordPress sites that have the Elated‑Themes Audrey plugin installed at version 1.5 or earlier are affected. WordPress core, other plugins, and non‑vulnerable themes are not directly impacted by this flaw.
Risk and Exploitability
Based on the description, it is inferred that the likely attack involves sending a crafted HTTP request to the theme’s file‑handling logic with a malicious file path; authentication is not required. The flaw’s CVSS score is 8.1, indicating high severity, while the EPSS score of less than 1 % suggests that exploitation events are currently uncommon. The vulnerability is not listed in CISA’s KEV catalog.
OpenCVE Enrichment