Описание
An unauthenticated attacker can make get_page_template() page-template resolution include a chosen readable local .php file outside the active theme directories. If relevant pre-conditions for both the server and the active theme are met, this can lead to RCE.
EPSS
Процентиль: 36%
0.0042
Низкий
8.1 High
CVSS3
Дефекты
CWE-98
Связанные уязвимости
CVSS3: 8.1
debian
2 дня назад
An unauthenticated attacker can make `get_page_template()` page-templa ...
EPSS
Процентиль: 36%
0.0042
Низкий
8.1 High
CVSS3
Дефекты
CWE-98