Tech article

A WordPress vulnerability scored 9.2/10 is present in all versions since 2016

No preview is available. Read the original article for the full story.

Hacker News | Sep 22, 2026 | vntok

Automated excerpt

An unauthenticated attacker can make get_page_template() page-template resolution include a chosen readable local . php file outside the active theme directories. The active child or parent theme contains a top-level directory whose name starts with page- (e. g. page-templates). A chosen local . php target file exists on the server and is readable by the web server account.

Selected automatically from source text; not independently written or fact-checked. Read the original for full context.

Read the original article

More tech news