Impact
The vulnerability is an unauthenticated Local File Inclusion flaw in the WordPress Barista theme up to version 2.5.1. An attacker can supply a crafted request that causes the theme to include arbitrary files from the server, allowing disclosure of sensitive files such as wp-config.php or database credentials and potentially enabling remote code execution if the included file is executable.
Affected Systems
The flaw affects the Edge‑Themes Barista theme for WordPress versions 2.5.1 and earlier. Any WordPress site that has installed Barista 2.5.1 or a lower version is vulnerable.
Risk and Exploitability
The CVSS score of 8.1 indicates a high severity. Because the flaw is unauthenticated and accessible via normal HTTP requests, an attacker does not need special privileges. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires only that external users can invoke the vulnerable page; if successfully exploited, the attacker can read or execute files on the server, compromising confidentiality, integrity, and availability. The likely attack vector is via normal HTTP requests to the vulnerable page.
OpenCVE Enrichment