Unauthenticated path traversal in page-template resolution leading to conditional RCE
Summary
WordPress has published GHSA-7hp8-65ch-5whp describing an unauthenticated path traversal vulnerability in page-template resolution that can lead to conditional remote code execution under certain preconditions. The advisory lists affected WordPress versions, patched versions, a high severity CVSS score, and CWE-98 as the underlying weakness, with fixes released across multiple branches including 7.1.2.