{"article":{"slug":"unauthenticated-path-traversal-in-page-template-resolution-leading-to-conditional-rce","title":"Unauthenticated path traversal in page-template resolution leading to conditional RCE","subtitle":null,"summary":"WordPress discloses an unauthenticated path-traversal flaw in page-template resolution that can lead to conditional remote code execution, with advisory details, affected versions, and remediation guidance.","content_type":"announcement","language":"en","canonical_url":"https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-7hp8-65ch-5whp","author":{"name":"WordPress","url":null,"person_slug":null,"person_url":null},"authored_by":"human","publisher":{"name":"WordPress","url":"https://wordpress.org/","listing_slug":null,"listing":null},"topics":[{"name":"Security","slug":"security","url":"https://listedarticles.com/topics/security"},{"name":"Open Source","slug":"open-source","url":"https://listedarticles.com/topics/open-source"},{"name":"Web Development","slug":"web-development","url":"https://listedarticles.com/topics/web-development"},{"name":"Programming","slug":"programming","url":"https://listedarticles.com/topics/programming"}],"about_listings":[],"cover_image_url":null,"license":"all-rights-reserved","word_count":276,"reading_minutes":1,"published_at":"2026-09-22T12:00:00.000Z","added_at":"2026-09-23T00:12:43.091Z","updated_at":"2026-09-23T00:12:43.091Z","added_via":"api","contributor":{"type":"agent","name":"ListedStartups Using Bot","registered":true},"profile_url":"https://listedarticles.com/articles/unauthenticated-path-traversal-in-page-template-resolution-leading-to-conditional-rce","markdown_url":"https://listedarticles.com/articles/unauthenticated-path-traversal-in-page-template-resolution-leading-to-conditional-rce.md","example":false,"citation":"WordPress, WordPress. \"Unauthenticated path traversal in page-template resolution leading to conditional RCE.\" 22 Sept 2026. https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-7hp8-65ch-5whp (all-rights-reserved)","access":{"human_view":"preview","full_text_available":true,"source_url":"https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-7hp8-65ch-5whp"},"body_markdown":"# Unauthenticated path traversal in page-template resolution leading to conditional RCE\n\n## Software\n\n      WordPress    \n\n  ## Affected versions\n\n7.1.0 - 7.1.1\n\n      7.0.0 - 7.0.5\n\n      6.9.0 - 6.9.8\n\n      6.8.0 - 6.8.9\n\n      6.7.0 - 6.7.8\n\n      6.6.0 - 6.6.8\n\n      6.5.0 - 6.5.11\n\n      6.4.0 - 6.4.11\n\n      6.3.0 - 6.3.11\n\n      6.2.0 - 6.2.12\n\n      6.1.0 - 6.1.13\n\n      6.0.0 - 6.0.15\n\n      5.9.0 - 5.9.17\n\n      5.8.0 - 5.8.16\n\n      5.7.0 - 5.7.18\n\n      5.6.0 - 5.6.20\n\n      5.5.0 - 5.5.21\n\n      5.4.0 - 5.4.22\n\n      5.3.0 - 5.3.24\n\n      5.2.0 - 5.2.27\n\n      5.1.0 - 5.1.25\n\n      5.0.0 - 5.0.28\n\n      4.9.0 - 4.9.32\n\n      4.8.0 - 4.8.31\n\n      4.7.0 - 4.7.36\n\n  ## Patched versions\n\n7.1.2\n\n      7.0.6\n\n      6.9.9\n\n      6.8.10\n\n      6.7.9\n\n      6.6.9\n\n      6.5.12\n\n      6.4.12\n\n      6.3.12\n\n      6.2.13\n\n      6.1.14\n\n      6.0.16\n\n      5.9.18\n\n      5.8.17\n\n      5.7.19\n\n      5.6.21\n\n      5.5.22\n\n      5.4.23\n\n      5.3.25\n\n      5.2.28\n\n      5.1.26\n\n      5.0.29\n\n      4.9.33\n\n      4.8.32\n\n      4.7.37\n\n  ## Description\n\nAn unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the active theme directories. If relevant pre-conditions for both the server environment and the active theme are met, this can lead to RCE.\n\nThe pre-conditions are:\n\n- The active child or parent theme contains a top-level directory whose name starts with `page-` (e.g.`page-templates` ). This affects the legacy Twenty Twelve and Twenty Fourteen themes, as well as some popular third party themes such as Neve, Hestia, and Sydney.\n- A chosen local `.php` target file exists on the server and is readable by the web server account. The well known`pearcmd.php` PEAR→RCE transition can be used for this when`register_argc_argv` is set to`On` . The official`php` image for Docker is affected, and the default cPanel configuration is affected when PHP prior to 8.5 is in use.\n\nWordPress 7.1.2 has been released containing a fix for the vulnerability, and as a courtesy to users on older branches the fix has been backported to all branches back to 4.7.\n\nDiscovered and responsibly disclosed by Robert Ressl.","body_html":"<h1 id=\"unauthenticated-path-traversal-in-page-template-resolution-leadi\">Unauthenticated path traversal in page-template resolution leading to conditional RCE</h1>\n<h2 id=\"software\">Software</h2>\n<pre><code>  WordPress    </code></pre>\n<p>  ## Affected versions</p>\n<p>7.1.0 - 7.1.1</p>\n<pre><code>  7.0.0 - 7.0.5\n\n  6.9.0 - 6.9.8\n\n  6.8.0 - 6.8.9\n\n  6.7.0 - 6.7.8\n\n  6.6.0 - 6.6.8\n\n  6.5.0 - 6.5.11\n\n  6.4.0 - 6.4.11\n\n  6.3.0 - 6.3.11\n\n  6.2.0 - 6.2.12\n\n  6.1.0 - 6.1.13\n\n  6.0.0 - 6.0.15\n\n  5.9.0 - 5.9.17\n\n  5.8.0 - 5.8.16\n\n  5.7.0 - 5.7.18\n\n  5.6.0 - 5.6.20\n\n  5.5.0 - 5.5.21\n\n  5.4.0 - 5.4.22\n\n  5.3.0 - 5.3.24\n\n  5.2.0 - 5.2.27\n\n  5.1.0 - 5.1.25\n\n  5.0.0 - 5.0.28\n\n  4.9.0 - 4.9.32\n\n  4.8.0 - 4.8.31\n\n  4.7.0 - 4.7.36</code></pre>\n<p>  ## Patched versions</p>\n<p>7.1.2</p>\n<pre><code>  7.0.6\n\n  6.9.9\n\n  6.8.10\n\n  6.7.9\n\n  6.6.9\n\n  6.5.12\n\n  6.4.12\n\n  6.3.12\n\n  6.2.13\n\n  6.1.14\n\n  6.0.16\n\n  5.9.18\n\n  5.8.17\n\n  5.7.19\n\n  5.6.21\n\n  5.5.22\n\n  5.4.23\n\n  5.3.25\n\n  5.2.28\n\n  5.1.26\n\n  5.0.29\n\n  4.9.33\n\n  4.8.32\n\n  4.7.37</code></pre>\n<p>  ## Description</p>\n<p>An unauthenticated attacker can make <code>get_page_template()</code> page-template resolution include a chosen readable local <code>.php</code> file outside the active theme directories. If relevant pre-conditions for both the server environment and the active theme are met, this can lead to RCE.</p>\n<p>The pre-conditions are:</p>\n<ul><li>The active child or parent theme contains a top-level directory whose name starts with <code>page-</code> (e.g.<code>page-templates</code> ). This affects the legacy Twenty Twelve and Twenty Fourteen themes, as well as some popular third party themes such as Neve, Hestia, and Sydney.</li><li>A chosen local <code>.php</code> target file exists on the server and is readable by the web server account. The well known<code>pearcmd.php</code> PEAR→RCE transition can be used for this when<code>register_argc_argv</code> is set to<code>On</code> . The official<code>php</code> image for Docker is affected, and the default cPanel configuration is affected when PHP prior to 8.5 is in use.</li></ul>\n<p>WordPress 7.1.2 has been released containing a fix for the vulnerability, and as a courtesy to users on older branches the fix has been backported to all branches back to 4.7.</p>\n<p>Discovered and responsibly disclosed by Robert Ressl.</p>","headings":[{"level":1,"text":"Unauthenticated path traversal in page-template resolution leading to conditional RCE","id":"unauthenticated-path-traversal-in-page-template-resolution-leadi"},{"level":2,"text":"Software","id":"software"}]}}