Impact
This vulnerability is an unauthenticated local file inclusion flaw in versions 1.1.1 and earlier of the WordPress Foton Core plugin. The flaw allows an attacker to specify arbitrary file paths in the plugin’s input parameters, enabling the server to read or, if a PHP file is located there, execute it. Because the plugin does not validate the path, the attacker can access sensitive files such as configuration files, user uploads, or system files, and potentially hijack the site or exfiltrate data.
Affected Systems
Affecting only the Mikado‑Themes Foton Core plugin, versions up to and including 1.1.1. Sites running this plugin on WordPress installations are susceptible. No other WordPress core or plugin versions are impacted.
Risk and Exploitability
The high CVSS score of 8.1 indicates substantial risk. Because the EPSS score is not available, the current exploitation probability cannot be quantified, but the lack of KEV listing suggests no widespread public exploitation yet. Nevertheless, the unauthenticated nature of the LFI makes it straightforward for automated scanners to detect and exploit. The vulnerability can be exploited via crafted URLs or form inputs that target the plugin’s file‑loading logic, allowing attackers to read sensitive files or execute arbitrary code if a PHP file can be read.
OpenCVE Enrichment