PT-2026-50411 · WordPress · Kastell
CVSS v3.1
8.1
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Kastell versions prior to 2.1
Description
An unauthenticated Local File Inclusion (LFI) issue exists in the Kastell WordPress theme. Local File Inclusion is a flaw that allows an attacker to include files on the server through the web application, potentially leading to the disclosure of sensitive information.
Recommendations
Update to a version later than 2.0.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Kastell