An unauthenticated attacker can create get_page_template() page-template resolution contain a chosen readable local .php document exterior the energetic theme directories. If applicable pre-conditions for the two the server surroundings and the energetic theme are met, this can guide to RCE.
The pre-conditions are:
- The energetic kid or genitor theme contains a top-level directory whose name starts alongside page- (e.g. page-templates). This affects the bequest Twenty Twelve and Twenty Fourteen themes, as fine as several famous third gathering themes specified as Neve, Hestia, and Sydney.
- A chosen local .php mark document exists on the server and is readable by the web server account. The fine known pearcmd.php PEAR→RCE passage can be used for this whenever register_argc_argv is set to On. The authoritative php depiction for Docker is affected, and the default cPanel configuration is affected whenever PHP previous to 8.5 is in use.
WordPress 7.1.2 has been released containing a fix for the vulnerability, and as a courtesy to users on older branches the fix has been backported to all branches rear to 4.7.
Discovered and responsibly disclosed by Robert Ressl.