← Back to feed
Vulnerabilities & PatchesEmerging1 sourceSep 23, 2026 · 13:55via LWN.net

Critical WordPress RCE vulnerability announced

Brief

A critical vulnerability has been discovered in WordPress 's get_page_template() function for page-template resolution that could allow remote-code execution (RCE) by an unauthenticated attacker, in some limited circumstances. The project has provided an update for the most recent branch of WordPress, as well as backports of the fix for branches back to 4. 7 .

See the vulnerability report for the conditions required for an RCE attack to be successful.

The vulnerability also affects the ClassicPress fork of WordPress, though a security update has not been provided for that project yet. LWN covered ClassicPress in

  • Users of either content-management system should update soon.
Read more on LWN.net