Skip to finding
important · Edge — WordPress

WordPress page-template traversal can write PHP and execute code without authentication on affected configurations.

Affects

WordPress Core, the PHP content-management system used by self-hosted websites.

The complete chain depends on an affected theme layout and a readable local execution target such as pearcmd.php, which can turn local inclusion into an attacker-controlled PHP write.

Detail and 4 sources
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Saturday, September 26, 2026