Impact
The Resido WordPress theme versions 1.5 and earlier contain an unauthenticated local file inclusion flaw. By manipulating file path parameters, an attacker can read arbitrary files on the local filesystem, and if the included file contains PHP code it can be executed in the context of the web server. This weakness is classified as CWE-98 and can result in code execution, data compromise or other severe impacts.
Affected Systems
The vulnerability affects any WordPress site that uses the SmartDataSoft Resido theme at a version less than or equal to 1.5. Sites running older or unpatched versions are exposed, while installations that have upgraded beyond 1.5 are not impacted.
Risk and Exploitability
The CVSS score of 8.1 indicates a high severity overall. The EPSS score is less than 1%, meaning the likelihood of exploitation in the wild is currently very low, and the vulnerability is not included in CISA's KEV catalog. Nonetheless, because the flaw is unauthenticated, it is inferred that a simple HTTP request could trigger it, allowing attackers that can reach the site to read sensitive files or execute malicious PHP. The risk remains significant until the theme is updated or the vulnerability is mitigated.
OpenCVE Enrichment