DigiNews

Tech Watch by Johan Denoyer

← Back to articles

Unauthenticated path traversal in page-template resolution leading to conditional RCE

Quality: 8/10 Relevance: 9/10

Summary

WordPress has published GHSA-7hp8-65ch-5whp describing an unauthenticated path traversal vulnerability in page-template resolution that can lead to conditional remote code execution under certain preconditions. The advisory lists affected WordPress versions, patched versions, a high severity CVSS score, and CWE-98 as the underlying weakness, with fixes released across multiple branches including 7.1.2.

🚀 Service construit par Johan Denoyer