Back

HIGH KEV

An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the active theme directories

Published Sep 22, 2026 ·Due Sep 28, 2026

Description

An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the active theme directories. If relevant pre-conditions for both the server and the active theme are met, this can lead to RCE.

Affected products

Remediation

Vendor solution

WordPress 7.1.2 has been released containing a fix for the vulnerability, and as a courtesy to users on older branches the fix has been backported to all branches back to 4.7.

Metrics

Weaknesses (1)

References (3)

Change history (1)
  1. CISA ADP
    • SSVC exploitation changed from none to active
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner hackerone
Published Sep 22, 2026
Updated Sep 26, 2026
Reserved Sep 9, 2026
CISA Vulnrichment
Updated Sep 25, 2026
NVD
Status Received
Modified Sep 22, 2026
Red Hat
Severity n/a
Public date n/a