Описание
An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the active theme directories. If relevant pre-conditions for both the server and the active theme are met, this can lead to RCE.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| wordpress | fixed | 7.1.2+dfsg1-1 | package |
Примечания
https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-7hp8-65ch-5whp
EPSS
Процентиль: 36%
0.0042
Низкий
Связанные уязвимости
CVSS3: 8.1
nvd
2 дня назад
An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the active theme directories. If relevant pre-conditions for both the server and the active theme are met, this can lead to RCE.
EPSS
Процентиль: 36%
0.0042
Низкий