← Back to events
ActiveTech

A WordPress vulnerability scored 9.2/10 is present in all versions since 2016

Photo: Hacker News

What happened

An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the active theme directories. If relevant pre-conditions for ...

Summary assembled by rule from the sources below

Why it's spreading

Sources