Skip to finding
important · WordPress — RCE

WordPress page-template traversal has moved from a conditional primitive to observed PHP writes and command payloads.

Affects

WordPress Core, a self-hosted PHP content-management system.

A public, unauthenticated request can traverse outside the theme template directory. On systems with the required theme and PHP settings, attackers include pearcmd.php, write PHP into a temporary directory, and include it again for execution.

Detail and 4 sources
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Sunday, September 27, 2026