WordPress 7.1.2 Patches Unauthenticated Local File Inclusion Flaw

WordPress 7.1.2 Patches Unauthenticated Local File Inclusion Flaw

WordPress 7.1.2 fixes GHSA-7hp8-65ch-5whp, an unauthenticated flaw in get_page_template() allowing inclusion of a chosen readable local .php file outside active theme directories. The fix, disclosed by Robert Ressl on Sept. 22, 2026, is backported to branches back to 4.7.

Published

Read at another depth