WordPress disclosed an unauthenticated path traversal vulnerability (GHSA-7hp8-65ch-5whp) that can lead to conditional remote code execution. The flaw allows attackers to manipulate file paths without authentication, potentially achieving RCE under certain conditions.
Background
WordPress powers over 40% of websites globally, making any unauthenticated RCE vulnerability a high-impact security issue affecting millions of sites worldwide.
- Source
- Hacker News (RSS)
- Published
- Sep 23, 2026 at 12:33 AM
- Score
- 8.0 / 10