Wordpress Alert: Local file inclusion in themes
A theme selects a PHP template from untrusted input. A readable file outside the expected theme path may be included.
What it looks like
A theme selects a PHP template from untrusted input.
Why it matters
A readable file outside the expected theme path may be included.
What to check
Review template selection and compare installed versions with advisories.
Documentation
This is an exploit pattern to check in installed components, not a claim that every WordPress site has this flaw. Confirm the product and version against its advisories before treating a site as affected. See OWASP path traversal reference, WordPress 7.1.2 security release.
- Categories: WordPress
- Tags: #WordPress Security, #File Security