Impact
Improper Control of Filename for Include/Require Statement in PHP allows the Nuss WordPress theme to include local files indiscriminately, meaning an attacker could read sensitive system files or execute arbitrary PHP code stored on the server. The weakness, classified as CWE‑98, gives high severity potential for a compromised web application. The vulnerability is exploitable if an attacker can influence file path parameters used by the theme during a page load.
Affected Systems
The issue affects the uxper Nuss WordPress theme, versions up to and including 1.3.6. Any WordPress site that has installed this theme within that version range is susceptible, regardless of other theme or plugin usage.
Risk and Exploitability
The CVSS score of 7.5 classifies this flaw as high severity, while the EPSS score of less than 1% indicates a very low likelihood of active exploitation in the wild at present. It is not currently listed in the CISA KEV catalog. Inference suggests the attack vector is web‑based, requiring the ability to influence the include path, which can often be achieved via crafted requests or via administrative access to the theme files.
OpenCVE Enrichment