An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the active theme directories. If relevant pre-conditions for both the server and the active theme are met, this can lead to RCE.
| Vendor | Product | Versions |
|---|---|---|
| WordPress | WordPress | 0 |
Downstream vendors/products affected by this vulnerability
| Vendor | Product | Source | Confidence |
|---|---|---|---|
| fedora | fedora linux | cert_advisory | 90% |
| open source | wordpress | cert_advisory | 90% |
Loading…