CyberRota Analysis
AI-GeneratedThe vulnerability in the Aqua theme for PHP allows for local file inclusion due to improper control of filenames in include/require statements, potentially enabling attackers to execute arbitrary code on the server. This high-severity flaw affects versions up to 5.1.2 and poses a significant risk to any installations of the Aqua theme. Website administrators using this theme should prioritize patching or upgrading to mitigate the risk of exploitation.
Original NVD Description
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in jwsthemes Aqua aqua allows PHP Local File Inclusion.This issue affects Aqua: from n/a through <= 5.1.2.