Post Syndicated from jzb original https://lwn.net/Articles/1096195/
A critical
vulnerability has been discovered in WordPress‘s get_page_template()
function for page-template resolution that could allow remote-code execution
(RCE) by an unauthenticated attacker, in some limited circumstances. The project
has provided an update for the most recent branch of WordPress, as well as
backports of the fix for branches back to 4.7. See the
vulnerability report for the conditions required for an RCE attack to be successful.
The vulnerability also
affects the ClassicPress fork of
WordPress, though a security update has not been provided for that project
yet. LWN covered ClassicPress in
2024. Users of either content-management system should update soon.