roots/wordpress is vulnerable to Path Traversal
92
Critical Risk
get_page_template() resolves a page template from attacker-influenced input without confining the resulting path to the active theme directories. An unauthenticated request can therefore cause WordPress to include a chosen readable local .php file outside the theme. When the active child or parent theme has a top-level directory whose name starts with page- (for example page-templates) and a suitable local PHP file is readable by the web server, that include becomes remote code execution. The fix restricts page-template resolution so paths cannot escape the theme directories.
You are affected if you are using a version that falls within the vulnerable range and the active child or parent theme contains a top-level directory whose name starts with page-. Reaching code execution also requires a readable local .php file on the server (for example pearcmd.php when register_argc_argv is On).
roots/wordpress is vulnerable to Path Traversal in versions 7.1 - 7.1.1, 7.0 - 7.0.5, 6.9 - 6.9.8, 6.8 - 6.8.9, 6.7 - 6.7.8, 6.6 - 6.6.8, 6.5 - 6.5.11, 6.4 - 6.4.11, 6.3 - 6.3.11, 6.2 - 6.2.12, 6.1 - 6.1.13, 6.0 - 6.0.15, 5.9 - 5.9.17, 5.8 - 5.8.16, 5.7 - 5.7.18, 5.6 - 5.6.20 and 0.0.1 - 5.5.21.
Upgrade the roots/wordpress library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.