What the vulnerability does
01Description
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Candid themes Grip.This issue affects Grip: from n/a through 1.0.9.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
What the vulnerability does
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Candid themes Grip.This issue affects Grip: from n/a through 1.0.9.
Explanation of Vulnerability in Simple Terms
Grip theme versions up to 1.0.9 contain a vulnerability that allows attackers to read sensitive data, modify site content, or disrupt service. The attack requires user interaction—typically a victim clicking a malicious link—and relies on specific conditions being met. No authentication is needed to initiate the attack.
What an attacker can do
Read sensitive data, modify site content, or cause the site to become unavailable.
Potential impact on your site
Site data could be exposed, content altered, or service disrupted if users are tricked into clicking malicious links.
Conditions required to exploit
Victim must click a malicious link or visit an attacker-controlled page; specific conditions must be present.
Key dates
External resources
Related vulnerabilities