WordPress Issues Patch for Critical Flaw That Can Enable Code Execution on Some Servers

WordPress has patched a critical vulnerability in all supported versions from 4.7 to 7.1.1 that allowed unauthenticated attackers to load PHP files from outside theme folders, potentially enabling code execution on some servers. The issue, fixed in release 7.1.2 and backported to earlier branches, stems from improper validation of template file names, and site owners are urged to update immediately as no workaround exists. The exploit depends on specific server and theme conditions, with no known active attacks reported as of the patch release.

https://thehackernews.com/2026/09/wordpress-issues-patch-for-critical.html

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top