What the vulnerability does
01Description
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Select-Themes Stockholm allows PHP Local File Inclusion.This issue affects Stockholm: from n/a through 9.6.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
What the vulnerability does
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Select-Themes Stockholm allows PHP Local File Inclusion.This issue affects Stockholm: from n/a through 9.6.
Explanation of Vulnerability in Simple Terms
Stockholm theme versions up to 9.6 contain a path traversal vulnerability that allows attackers to read arbitrary files from the server without authentication. By crafting malicious requests, an attacker can access sensitive files outside the intended directory structure. The vulnerability requires specific conditions to exploit but can expose configuration files, database credentials, and other sensitive data.
What an attacker can do
Read arbitrary files from the server, including configuration files and sensitive data.
Potential impact on your site
Attackers can access sensitive files like wp-config.php, database backups, or private keys without logging in.
Conditions required to exploit
Network access to the site; no authentication required, but exploitation requires specific request conditions.
Key dates
External resources
Related vulnerabilities