WordPress Mamita theme <= 1.0.9 - Local File Inclusion vulnerability
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 8.1epss 0.6%
exploitation probability
0.6%top 57% of all CVEs
observed exploitation
nono source reports it
In short
The WordPress Mamita theme up to version 1.0.9 has a flaw that lets attackers include and execute local files on the server through PHP code. This can expose sensitive information or allow unauthorized actions on the website.
Technical detail
A PHP Local File Inclusion (LFI) vulnerability exists in the Mamita theme's file inclusion mechanism due to improper input validation. An attacker can manipulate file path parameters to include arbitrary local files, potentially leading to information disclosure, code execution, or privilege escalation depending on accessible files and server configuration.
Summary generated and translated by AI from the official description.
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Mamita mamita allows PHP Local File Inclusion.This issue affects Mamita: from n/a through <= 1.0.9.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
AncoraThemes · Mamita