
WordPress 7.1.2 Fixes Login-Free File Access Bug
WordPress 7.1.2 fixes flaw GHSA-7hp8-65ch-5whp in get_page_template(), a function that picks page layouts. It let visitors with no login load any readable .php file on the server outside the current theme folders. Reported by Robert Ressl on Sept. 22, 2026, the patch is backported to versions back to 4.7.
Published