Multiple Themes by bslthemes <= Various Version - Unauthenticated Local File Inclusion
criticalMultiple themes by bslthemes for WordPress are vulnerable to Local File Inclusion in various versions. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sens...
- CVSS:
- 9.8
- Affected:
- up to 1.4.0
- Fixed in:
- 1.4.1
- Disclosed:
- May 20, 2025