Impact
The Aalto theme for WordPress contains a flaw where the filename used in a PHP include or require statement is not validated, allowing illicit local file inclusion. This weakness can be exploited to read arbitrary server files or execute code, potentially compromising the WordPress installation.
Affected Systems
All WordPress sites that installed the Aalto theme from its initial release through version 1.8 are affected. The theme is identified as Edge‑Themes Aalto and any installation with a version number equal to or less than 1.8 falls within the vulnerable range.
Risk and Exploitability
The CVSS score of 7.5 indicates a high risk, while an EPSS score of less than 1% shows a low current exploitation probability. The vulnerability is not listed in CISA KEV. Attackers would need to supply a crafted filename or path value, likely via a publicly exposed parameter that is directly used in an include or require call. Successful exploitation could allow reading of sensitive files or execution of arbitrary PHP code on the server.
OpenCVE Enrichment