CyberRota Analysis
AI-GeneratedThe vulnerability in Select-Themes Struktur allows for local file inclusion due to improper control of filenames in PHP include/require statements, potentially enabling an attacker to execute arbitrary PHP code on the server. This poses a significant risk for any installations of Struktur version 2.5.1 or earlier, as it could lead to unauthorized access and manipulation of sensitive files. Organizations using this theme should prioritize immediate updates to mitigate the risk of exploitation.
Original NVD Description
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Select-Themes Struktur allows PHP Local File Inclusion. This issue affects Struktur: from n/a before 2.7.