Skip to finding
important · Research

WordPress page-template traversal can lead to conditional unauthenticated PHP execution.

Affects

WordPress Core, the PHP content-management system used by public websites.

A valid page_id and double-encoded traversal can make template resolution include readable PHP outside the active theme.

Detail and 3 sources

Code execution additionally requires a qualifying theme layout, a usable local inclusion target, PEAR, and register_argc_argv; under those conditions pearcmd.php can write PHP that a second request executes as the web-server account.

WordPress has published a fix.

Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Tuesday, September 29, 2026