Impact
A mismanagement of the filename used in a PHP include statement in the Select‑Themes SetSail theme allows a local file inclusion. This weakness, identified as CWE‑98, means that an attacker can specify an arbitrary path in a request that the theme will then read from the server. The vulnerability could be exploited to read contents of files on the web server’s filesystem, potentially exposing sensitive configuration or data files. The CVE documentation does not assert that the inclusion leads to execution of malicious code, only that files can be read.
Affected Systems
The vulnerability affects the WordPress SetSail theme from Select‑Themes, from its initial release through version 2.1 at risk.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity. The EPSS score is below 1%, suggesting a low but non‑zero probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the most plausible attack vector is via a web request that supplies an attacker‑controlled disclosure of sensitive files.
OpenCVE Enrichment