Impact
The flaw resides in the AI Hub theme, where an improper validation of file paths in the download handler permits a client to obtain any file stored on the server. If accessed, this could expose configuration files, credentials, or other sensitive data, and may be exploited further if the downloaded files contain executable content. The weakness corresponds to CWE‑22: Path Traversal.
Affected Systems
Any WordPress site using the LiquidThemes AI Hub theme version 1.3.10 or earlier.
Risk and Exploitability
The CVSS score of 7.7 indicates a high impact vulnerability. The EPSS score is not available and the flaw is not listed in CISA KEV, so public exploitation rates are uncertain. Likely, a remote attacker could send a crafted HTTP request to the vulnerable download endpoint; the description does not specify authentication requirements, so the attack vector may require or not require credentials, which is inferred from the typical WordPress file‑download functionalities.
OpenCVE Enrichment