
WordPress 7.1.2 Patches Unauthenticated Local File Inclusion Flaw
WordPress 7.1.2 fixes GHSA-7hp8-65ch-5whp, an unauthenticated flaw in get_page_template() allowing inclusion of a chosen readable local .php file outside active theme directories. The fix, disclosed by Robert Ressl on Sept. 22, 2026, is backported to branches back to 4.7.
Published