1
WordPress: Unauthenticated path traversal leading to conditional RCE
WordPress 7.1.2 patches an unauthenticated path‑traversal in get_page_template() that lets an attacker include arbitrary readable PHP files outside the theme when a top‑level "page-" directory exists. The bug can lead to remote code execution on systems with a readable PHP payload (e.g., pearcmd.php) and register_argc_argv enabled.
Hacker News front pagegithub.com1 minHN16585