WordPress Woopy theme <= 1.2 - Local File Inclusion vulnerability
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 8.1epss 0.5%
exploitation probability
0.5%top 59% of all CVEs
observed exploitation
nono source reports it
In short
The Woopy WordPress theme up to version 1.2 contains a vulnerability that allows attackers to include and execute local files on the server. This can lead to unauthorized access to sensitive files or remote code execution if exploited.
Technical detail
CWE-98 (improper control of filename for include/require statements) in Woopy <= 1.2 allows local file inclusion (LFI) through inadequately sanitized include/require parameters. An attacker with web access can manipulate file path inputs to include arbitrary local files, potentially leading to information disclosure or code execution depending on file accessibility and context.
Summary generated and translated by AI from the official description.
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Woopy woopy allows PHP Local File Inclusion.This issue affects Woopy: from n/a through <= 1.2.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
AncoraThemes · Woopy