Unauthenticated path traversal in page-template resolution leading to conditional RCE

Software

  WordPress    

## Affected versions

7.1.0 - 7.1.1

  7.0.0 - 7.0.5

  6.9.0 - 6.9.8

  6.8.0 - 6.8.9

  6.7.0 - 6.7.8

  6.6.0 - 6.6.8

  6.5.0 - 6.5.11

  6.4.0 - 6.4.11

  6.3.0 - 6.3.11

  6.2.0 - 6.2.12

  6.1.0 - 6.1.13

  6.0.0 - 6.0.15

  5.9.0 - 5.9.17

  5.8.0 - 5.8.16

  5.7.0 - 5.7.18

  5.6.0 - 5.6.20

  5.5.0 - 5.5.21

  5.4.0 - 5.4.22

  5.3.0 - 5.3.24

  5.2.0 - 5.2.27

  5.1.0 - 5.1.25

  5.0.0 - 5.0.28

  4.9.0 - 4.9.32

  4.8.0 - 4.8.31

  4.7.0 - 4.7.36

## Patched versions

7.1.2

  7.0.6

  6.9.9

  6.8.10

  6.7.9

  6.6.9

  6.5.12

  6.4.12

  6.3.12

  6.2.13

  6.1.14

  6.0.16

  5.9.18

  5.8.17

  5.7.19

  5.6.21

  5.5.22

  5.4.23

  5.3.25

  5.2.28

  5.1.26

  5.0.29

  4.9.33

  4.8.32

  4.7.37

## Description

An unauthenticated attacker can make get_page_template() page-template resolution include a chosen readable local .php file outside the active theme directories. If relevant pre-conditions for both the server environment and the active theme are met, this can lead to RCE.