• Critical WordPress RCE vulnerability announced

    From LWN.net@618:250/24 to All on Thu Sep 24 06:40:09 2026

    A critical
    vulnerability has been discovered in WordPress's get_page_template()
    function for page-template resolution that could allow remote-code execution (RCE) by an unauthenticated attacker, in some limited circumstances. The project
    has provided an update for the most recent branch of WordPress, as well as backports of the fix for branches back to 4.7. See the
    vulnerability report for the conditions required for an RCE attack to be successful.

    The vulnerability also
    affects the ClassicPress fork of
    WordPress, though a security update has not been provided for that project
    yet. LWN covered ClassicPress in
    2024. Users of either content-management system should update soon.

    https://lwn.net/Articles/1096195/
    --- SBBSecho 3.37-Linux
    * Origin: Palantir * palantirbbs.ddns.net * Pensacola, FL * (618:250/24)