Impact
The Fuelthemes Werkstatt WordPress theme contains an improper control of the filename used in PHP include or require statements. This flaw allows an attacker to supply a path that is passed directly to an include call, resulting in a Local File Inclusion vulnerability. The attacker could read arbitrary files on the server, and based on the description, it is inferred that if a malicious file is placed in an accessible location, remote code execution might be achieved.
Affected Systems
This issue affects the Fuelthemes Werkstatt theme for WordPress, from the earliest available release up through version 4.8.3. Users running any of those versions are vulnerable, while newer releases are not known to contain this flaw.
Risk and Exploitability
The CVSS score of 8.1 indicates a high severity for the vulnerability. Attack execution is likely local and requires the ability to supply a path that is unfiltered before inclusion. No EPSS score is available, so the precise likelihood of exploitation cannot be quantified, and the vulnerability is not listed in the CISA KEV catalog. The high CVSS, coupled with the possibility of local file read and inferred code execution, warrants treating this flaw with the same caution as other high‑severity local file inclusion problems.
OpenCVE Enrichment