What is confirmed
A core path-traversal flaw with conditional code-execution impact
WordPress says an unauthenticated attacker can make page-template resolution include a chosen readable local PHP file outside the active theme directories. When the necessary theme and server conditions are also present, that local-file inclusion can become remote code execution.
The project fixed the issue in WordPress 7.1.2 and published security backports for supported older branches through 4.7. WordPress recommends updating immediately and reminds administrators that only the latest branch is actively supported.
Threat Field Notes assessment
Exposure
The version, theme, and PHP environment all matter
| Question | Why it matters | Evidence to collect |
|---|---|---|
| Which WordPress branch is actually installed? | A recently patched site can still be affected if it stopped at 7.1.1 or an older unfixed branch. | Dashboard and command-line version, package records, deployment history, and confirmation from managed hosts. |
| Which parent and child themes are active? | The published attack path depends on a suitable theme directory and a readable PHP target. | Active-theme paths, parent-child relationship, template directories, and recent theme changes. |
| What does the web PHP runtime permit? | The demonstrated route to code execution needed additional server-side components and settings. | Effective web-runtime configuration, readable PHP utilities, writable locations, and service-account permissions. |
Check the PHP configuration used by the web server, not only the command-line runtime. A hardening change that breaks one demonstrated chain does not remove the underlying WordPress defect; it is supplementary to the core update.
Response
Patch broadly and verify the outcome
- 1
Find every site and owner. Include development, campaign, regional, and agency-managed sites. Record the installed WordPress branch and who is accountable for the update.
- 2
Install the fixed release. Move to 7.1.2 or the vendor-listed fixed release for the maintained branch. Treat old-branch backports as immediate risk reduction, not a substitute for a supported-version plan.
- 3
Verify from the running site. Confirm the effective version after the update and exercise important publishing, authentication, caching, and theme paths. Do not rely only on an automatic-update setting.
- 4
Review the pre-patch window. Look for unusual page-template requests, PHP errors, newly created or changed PHP files, unexpected administrator actions, and outbound traffic from the web process. Preserve logs before rotation.
Editorial note
How this analysis was prepared
This story was surfaced by The Cyber Security Hub newsletter. Threat Field Notes checked the WordPress release, branch documentation, and public advisory, then wrote this independent defender response. The newsletter was used as a lead, not as the article text.