Impact
TheGem Theme Elements plugin contains an improper control of the filename used in PHP include/require statements. An attacker can supply crafted input to include arbitrary local files on the server. This weakness, identified as CWE-98, can lead to disclosure of sensitive files. Based on the description, it is inferred that if a PHP file is included, it could be executed, but this is not explicitly stated.
Affected Systems
CodexThemes TheGem Theme Elements (for Elementor) plugin for WordPress is affected. All releases up to and including version 5.11.1 are vulnerable. The plugin is used in WordPress sites that incorporate the TheGem Theme Elements interface via Elementor.
Risk and Exploitability
The CVSS score of 7.5 classifies the issue as high severity, while the EPSS score is below 1% indicating a very low current exploitation probability. The vulnerability is not listed in CISA KEV. Based on the description, it is inferred that an attacker might craft a request that triggers the vulnerable include, allowing access to any local file or execution of PHP code if a suitable file exists on the server.
OpenCVE Enrichment