Impact
The Struktur theme for WordPress contains an improper control of filenames used in PHP include/require statements (CWE‑98). This flaw allows an attacker to supply an arbitrary local file path, leading to sensitive information disclosure or the execution of malicious code if the attacker controls the included content (the local code execution possibility is inferred). The vulnerability is classified as a PHP Local File Inclusion, which directly compromises file confidentiality and integrity, and can ultimately affect system availability if exploited repeatedly.
Affected Systems
The flaw affects the Struktur theme versions distributed by Select‑Themes from the earliest known release up through 2.5.1. Any WordPress installation that has this theme enabled is vulnerable regardless of its WordPress or PHP version. The issue does not evolve with newer WordPress releases unless the theme remains unchanged.
Risk and Exploitability
The EPSS exploitation probability of the vulnerability is 0.0037, indicating a very low likelihood of exploitation, and it is not listed in the CISA KEV catalog. The CVSS score of 7.5 indicates substantial severity. The likely attack vector involves manipulating a query string or a parameter accepted by the theme, but this is inferred from typical LFI patterns and not explicitly stated in the advisory.
OpenCVE Enrichment