Impact
The vulnerability allows an unauthenticated attacker to include arbitrary local files through the Verdure Core plugin in WordPress. This can expose sensitive server data or enable the execution of attacker‑supplied code, depending on the files accessed. The weakness is identified as CWE‑98 and is classified as a high‑severity flaw with a CVSS score of 8.1.
Affected Systems
The vulnerability affects the Elated‑Themes Verdure Core plugin for WordPress, specifically versions 1.2 and all earlier releases.
Risk and Exploitability
The CVSS score of 8.1 indicates a high impact potential. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is remote, where an attacker can craft a request to the plugin’s file inclusion endpoint without needing authentication. If successful, the attacker can read arbitrary files and may execute code from included files, thereby compromising the integrity and confidentiality of the system.
OpenCVE Enrichment