johnpbloch/wordpress-core is vulnerable to Path Traversal
92
Critical Risk
get_page_template() resolves a page template from attacker-influenced input without confining the resulting path to the active theme directories. An unauthenticated request can therefore cause WordPress to include a chosen readable local .php file outside the theme. When the active child or parent theme has a top-level directory whose name starts with page- (for example page-templates) and a suitable local PHP file is readable by the web server, that include becomes remote code execution. The fix restricts page-template resolution so paths cannot escape the theme directories.
You are affected if you are using a version that falls within the vulnerable range and the active child or parent theme contains a top-level directory whose name starts with page-. Reaching code execution also requires a readable local .php file on the server (for example pearcmd.php when register_argc_argv is On).
johnpbloch/wordpress-core is vulnerable to Path Traversal in versions 7.1.0 - 7.1.1, 7.0.0 - 7.0.5, 6.9.0 - 6.9.8, 6.8.0 - 6.8.9, 6.7.0 - 6.7.8, 6.6.0 - 6.6.8, 6.5.0 - 6.5.11, 6.4.0 - 6.4.11, 6.3.0 - 6.3.11, 6.2.0 - 6.2.12, 6.1.0 - 6.1.13, 6.0.0 - 6.0.15, 5.9.0 - 5.9.17, 5.8.0 - 5.8.16, 5.7.0 - 5.7.18, 5.6.0 - 5.6.20, 5.5.0 - 5.5.21, 5.4.0 - 5.4.22, 5.3.0 - 5.3.24, 5.2.0 - 5.2.27, 5.1.0 - 5.1.25, 5.0.0 - 5.0.28, 4.9.0 - 4.9.32, 4.8.0 - 4.8.31 and 4.7.0 - 4.7.36.
Upgrade the johnpbloch/wordpress-core library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.