WordPress Madara Theme < 2.2.2.1 - Local File Inclusion
Madara WordPress theme <= 2.2.2 contains a local file inclusion vulnerability caused by improper sanitization of the 'template' parameter, letting unauthenticated attackers execute arbitrary files on the server, exploit requires crafted request.
PoC 已收录Madara
CVSS—EPSS 10.4%