A 9.2-rated WordPress flaw has lurked in every version since 2016
A WordPress vulnerability scored 9.2/10 is present in all versions since 2016
An unauthenticated path traversal in WordPress's page-template resolution lets an attacker include a local .php file outside the active theme, potentially achieving remote code execution. It affects versions back to 4.7, including popular themes like Twenty Twelve, Twenty Fourteen, Neve, Hestia, and Sydney. WordPress 7.1.2 patches it, with backports to all branches. Discovered by Robert Ressl.
An unauthenticated attacker can make get_page_template() page-template resolution include a chosen readable local .php file outside the active theme directories.
- zelphirkalt
These are the reason, why every easily reachable web server will be spammed with /something/something.php?somearg=someval. If I had to guess, which software on the web has been the most exploitable over all of the web's history, WP would surely be among the top candidates. Maybe right after MS Teams or Sharepoint or some stuff like that.
- beezle
"WordPress 7.1.2 has been released containing a fix for the vulnerability, and as a courtesy to users on older branches the fix has been backported to all branches back to 4.7"
As a courtesy, I try not to say more than one bad thing about WP every day. FWIW about 1/3 of installs are not on the recent 7 branch.
- cyphar
This kind of bug pathology is incredibly common in all sorts of programs and is the reason (disclaimer: self-plug) I wrote libpathrs[1].
Sadly, almost all language standard libraries do not provide the right abstractions for dealing with files (the primary focus is on global paths as opposed to scoped paths or file descriptors / file handles) so it's little surprise bugs like these just keep popping up every few weeks.
To eliminate these from your codebase you need to rethink and really focus on being aware of how you deal with files. If the program you're writing has root privileges then you need to be more careful about misdirected writes to /proc or other pseudofilesystems.
- random_savv
I am so happy that I asked Codex to rewrite our website as Hugo templates which allowed us to statically host it and get rid of Wordpress. So much stress gone!
- chrismorgan
The patch (identified from https://github.com/WordPress/wordpress-develop/compare/7.1.1...):
https://github.com/WordPress/wordpress-develop/commit/9c4e85...
- Luker88
Wordpress was the go-to for people who did not know programming and wanted a website.
Has anything changed with AI? It did help me switch from wp to rust+dioxus, but I am a programmer.
- vntok
Ironically, this 9 years old comment on the official documentation page of one of the affected functions perfectly describes both the nature and remediation of this major security flaw:
> Paul Ryan 9 years ago
> Note that locate_template() does not prevent directory traversal attacks, so if you’re passing a user-provided template name to the function, be sure to verify that it’s from one of the three appropriate locations (active theme directory, parent theme directory, or /wp-includes/theme-compat/ directory).
https://developer.wordpress.org/reference/functions/locate_t...
- iLoveOncall
WordPress really is a piece of garbage software, and if you've ever developed plugins for it it is soooo apparent.
The documentation is a perfect reflection of the absolute mess of spaghetti code that it is, half of the methods that you will use constantly when developing plugins are undocumented, even untyped. It's literally unusable.
I know WordPress is good thanks to its ecosystem, but really, really, do NOT use it.