An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the active theme directories. If relevant pre-conditions for ...

240 points•vntok•8 days ago•132 comments•

132 comments

vntok8 days ago
Ironically, this 9 years old comment on the official documentation page of one of the affected functions perfectly describes both the nature and remediation of this major security flaw:

> Paul Ryan 9 years ago

> Note that locate_template() does not prevent directory traversal attacks, so if you’re passing a user-provided template name to the function, be sure to verify that it’s from one of the three appropriate locations (active theme directory, parent theme directory, or /wp-includes/theme-compat/ directory).

https://developer.wordpress.org/reference/functions/locate_t...

erichocean8 days ago
It's a mystery how this exploit was found.

/sarc

foul8 days ago
Ahahah I remember to have patched themes for clients by hand, years ago. A different time, where a core team would for whatever reason leave security holes around to be sure you need three frameworks around their pile of dung code.
IshKebab8 days ago
I wonder if they'll add a `locate_template_safe()` function to "fix" it. :D
zelphirkalt8 days ago
These are the reason, why every easily reachable web server will be spammed with /something/something.php?somearg=someval. If I had to guess, which software on the web has been the most exploitable over all of the web's history, WP would surely be among the top candidates. Maybe right after MS Teams or Sharepoint or some stuff like that.
toyg8 days ago
TBF, some of it is structural: if you're the most popular anything on the internet, you'll be the most attacked and the most exploited, and hence the most exploitable.
0xbadcafebee7 days ago
Most attacked, sure. Most exploited? You get out of it what you put into it. If you work to make it more secure, it will stay more secure, popular or not.

WordPress is a software design from the early 2000's - and not a particularly good example. Even back then there were more secure designs.

Take QMail for example. A simple design, it had security baked in from the start, and remains one of the most secure software packages in history. This exploit would have been prevented if WordPress had followed QMail's security designs. Enforced data flow, avoidance of parsing, eliminating untrusted code, and eliminating bugs by choosing code paths with fewer variables, would've all prevented this bug.

DJB wrote a paper on QMail[1] to try to explain what worked and what was unnecessary. Anyone implementing new software (and wants it to be secure) should consider these [and other] design points. Popular software doesn't have to be bad software. [1] https://cr.yp.to/qmail/qmailsec-20071101.pdf

teunispeters8 days ago
That's bad designs for you. Assume that just because it's widely visible, must mean it has exploits. (this is the only point on that list I'll call "that's bad logic" on).
acomjean8 days ago
And it's very extensible. With that power and flexibility come exploits
fragmede8 days ago
How many times has Google been hacked? It's not zero, but just because something is popular doesn't mean it has to get exploited. Repeatedly.
atoav8 days ago
Yes and Wordpress is a pile of garbage.
reaperducer8 days ago
If I had to guess, which software on the web has been the most exploitable over all of the web's history, WP would surely be among the top candidates.

People on HN love to talk smack about WordPress. After all these years, it's as much a reflex as shouting "walled garden!" every time there's an Apple story.

Yet some of the biggest web sites on the internet run WordPress, and more importantly, some of the biggest hacking targets on the internet run WordPress.

Prime example: whitehouse.gov.

If you know what you're doing, WordPress fine. The same is true with every other piece of technology out there.

But people on HN like to lump the good in with the bad because everything is binary.

chrismorgan8 days ago
WordPress’s security model is distilled insanity, concentrated vulnerability. You’re supposed to give your site write access to its code, which turns almost any vulnerability into complete and persistent site takeover. Not to mention how many things will store code in the database and execute it from there, and how much of its design is fragile as anything, and how many plugins, often popular ones, do obviously dumb things that would not have been possible in most ecosystems.

Drupal (also popular in governments and such), by contrast, will check that it can’t write to anything but its designated file uploads directory, and complain if it can, and has careful guidance around avoiding letting uploads be accidentally executable too. The blast radius of the typical vulnerability, and the possibility of persistent takeover, is drastically reduced.

It’s possible to use C correctly, but in practice using it invites security problems, because it’s frightfully easy to make subtle but disastrous mistakes, even for experts, so there are reasons why people are moving to safe languages.

WordPress is that kind of bad. It has always been bad, though it’s somewhat less bad than it used to be. Some of its badness is a part of how it got popular.

imnotr0b0t8 days ago
Yeah, I agree that with the right expertise you can keep WordPress safe, and the White House is a good example of that. But the problem is the WP ecosystem and defaults push people without that expertise to install plugins and themes, and "if you know what you're doing" is the exception, not the rule for its user base
spogbiper8 days ago
> If you know what you're doing, WordPress fine.

Probably true, but for whatever reason Wordpress seems to attract an awful lot of people that do not know what they are doing

zelphirkalt8 days ago
I think the problem is of another nature:

People who _don't_ know what they are doing are using WP for every project, that they touch, because it is all they know. Given WPs database design, the assumptions baked into that, and the complications resulting from that, make anything other than a posts and pages website a PITA.

This in turn requires one to install shitty plugins, or spend time developing a minimalistic solution to each new challenge. With every plugin the attack surface grows, and the vast majority of larger WP sites is this cobbled together mess of WP plugins, having some WP expert trying to make them all work together without stepping on each other's toes, while hopelessly falling behind on updates, because updates could, and _will_ break things.

People only knowing PHP and WP, try to use WP as a sledgehammer, not realizing that hammer actually being made out of glass. Very few plugins are actually minimalistic, no-bloat, safe, well-developed. Lots of those plugins are 80% marketing fluff and wanting to make a business out of worse than mediocre code bases. That's also due to many people in that community being exactly those, who don't know anything but WP.

Even normal core WP updates can break the legality of ones site. I have had that at some point, where after some WP update it started loading emojis from a friggin third party, to replace the unicode symbol I had used. I was furious, because this needs to be part of the data protection policies/statements. One does not simply load a third party shit, replacing what the dev actually put there, which was just a unicode symbol. That's an idiotic thing to do. If I wanted third-party emojis, I would have included them myself.

Finally, some big pages run on WP says not much, given the catastrophic state of many websites. whitehouse.gov is laughably badly made. Another complete failure. The first thing I see that it loads Google tags manager. A government site loading shit.

    fonts.googleapis.com
    googletagmanager.com
    gstatic.com
    parsely.com
All this crap. And this is only what is loaded right out of the box. I haven't even allowed their shitty scripts to run yet.

And the navigation font is tiiiny. What a horrendous design.

When I click on some navigation link, it wants to go to:

    https://www.whitehouse.gov/wp-content/uploads/2026/01/Wide_Site_Primary_02.mp4
lol. From nav directly to some mp4 video?? Not a URL of a page, which then would display the video, but a URL directly to a video? Good that my noscript blocked media on that domain!

If it is a prime example, then it is a prime example of a very shitty made website, by people, who don't know what they should be doing.

So all this shows is one can make a shitty site using WP. Great. I am sure one can also make a not shitty site using WP. Like you say, _"If you know what you are doing ..."_. Just that most WP people don't. They don't know how to not make a mess, or choose the short-term easy way out, and install tons of shitty plugins. Many of them just have to put things up once initially and are paid, or hold the hand open for some maintenance fee they extract, required only due to how badly made these WP sites are.

nom8 days ago
The access log of public http servers is truly interesting to watch.

You know that the scripts doing it are optimized for success rate, so the types of requests they send give you an impression of what's actually out there.

It's clear to me that once we finally achieve rogue AGI, it is going to propagate through unpatched WordPress WooCommerce instances.

lyu072828 days ago
It seems the most common issue of them all is an exposed .env file by that measure.
jamesfinlayson8 days ago
Yep I see this at work pretty regularly - a SpringBoot log file full of requests for all sorts of things (mostly WordPress but I think some IIS as well).
mitxela8 days ago
Not success rate per request though.
traceroute668 days ago
> WP would surely be among the top candidates

And its closely related cousin, Joomla.

bombcar8 days ago
Joomla makes WP look like Fort Knox.
ErroneousBosh7 days ago
Every so often I switch on the nginx endpoint that serves a 10TB zipbomb to clients that request anything `wp-*` that 404s (which is everything on my sites, I don't run WordPress).

Sometimes the same IP address hits two or three URLs before going dead.

Sure is quiet around here at night.

beezle8 days ago
"WordPress 7.1.2 has been released containing a fix for the vulnerability, and as a courtesy to users on older branches the fix has been backported to all branches back to 4.7"

As a courtesy, I try not to say more than one bad thing about WP every day. FWIW about 1/3 of installs are not on the recent 7 branch.

EGreg8 days ago
There was a time I looked up to Matt Mullenweg, but never to Wordpress.

I've been building https://github.com/Qbix since 2008 and let me tell ya, I took a lot of great ideas from Drupal, Kohana, Symfony, etc. But never Wordpress. It's just ... a mess. Wordpress just won by being first, basically. Kind of like Bitcoin.

PS: Years ago, I hired a guy in Pakistan to work with me on some Wordpress sites, for clients. I thought that the Divi theme and basic Wordpress would be secure. Every one of those sites got pwned, badly. Sure, maybe it was the plugins. But why take the chance? In 2026 it's way past time to not have to worry about basic security.

tweetle_beetle7 days ago
A tale as old as time... I made money by outsourcing to third party labour to a much cheaper country than my own, using a third party low code theme builder and third party plugins I didn't vet. All of my customers got hacked.

This is the problem WordPress faces - it's powerful enough for people to get stuff done on a shoestring. But the professionals who want to do things on a shoestring are also likely cutting corners elsewhere (hosting, backups, security, etc). In many cases there's money changing hands and it's easier to blame WordPress than poor decision making.

I have more sympathy for those building with it on a shoestring for personal/charitable projects who may lack the skills/experience to follow https://developer.wordpress.org/advanced-administration/secu.... They're probably better off on Wix or Squarespace.

pmlnr8 days ago
WP won by having a very simple but flexible admin page.

Drupal admin was not for humans back then.

krapp8 days ago
Wordpress wasn't even first, Movable Type was the big thing before it.
jeroenhd7 days ago
WordPress doesn't to LTS. WordPress usually backports security fixes to older branches (like the 6.x branches) but going all the way back to 4.x isn't something they'll do for every fix. Who knows how many bugs lie in wait for older versions that are out of support.

If you run WordPress, you should be aware of this already. Either upgrade to the latest versions, constantly and quickly, or have extremely restrictive WAFs up and ready. Especially if you have any plugins installed (as those are usually where the WordPress exploits are coming from).

I'd recommend everyone unhappy only finding out about WordPress' long-standing support policy to ask their money back.

random_savv8 days ago
I am so happy that I asked Codex to rewrite our website as Hugo templates which allowed us to statically host it and get rid of Wordpress. So much stress gone!
woah8 days ago
You can make the most intricate drag and drop admin interfaces to allow the editor to customize everything, and they will still call you to put up every post, so might as well go static
rsolva8 days ago
This! My customers love that they can call and email me to update their websites, not having to remember usernames, passwords and how the publish interface works. Wordpess or static does not really matter in many cases.
vntok8 days ago
Sorry in advance if you were joking, but for readers who aren't in the know: Hugo had, in fact, two 9.3 CVSS vulnerabilities just 11 days ago...

https://app.opencve.io/cve/CVE-2026-89259

https://app.opencve.io/cve/CVE-2026-89258

abound8 days ago
To be clear, those are CVEs in the tooling, not in the generated static sites. Not great, but very different from this WordPress CVE
BadBadJellyBean8 days ago
I have full control over the inputs for hugo and the output is pure static HTML. It's better if there are no CVEs but I really don't sweat these. My Hugo template runs 100% pure CSS and no JS.
benregenspan8 days ago
This seems like a really good example of Base CVSS scores not telling us much on their own.

For the Wordpress RCE (nominally CVSS 9.2), it looks like many standard deployments of WordPress would be affected, barring extra mitigations. But in the case of these Hugo ones (9.3), it looks like very specific circumstances (anti-mitigations, if you will) are needed. E.g. running arbitrary builds of untrusted user content without a sandbox; running it in a GitHub workflow against PRs from untrusted contributors, etc.

toast08 days ago
When I finally got approval to rewrite the company blog from Wordpress into something that was mostly static, it was the best week. I used PHP to do mobile/desktop and language selection, because PHP is pretty useful, and it can be pretty fast and secure if you only do simple things.

Never had to worry again about sequencing updates where the update changed the database schema and I had a cluster of 6 web servers. Never had to worry anymore about long ass load times because the web servers were in 3 colos and wordpress wouldn't play nice with local read only mysql replicas. No more worries about why pingbacks and comments keep showing up in the database even those those features were turned off; at least they weren't showing up in a moderation queue, but still.

themeiguoren8 days ago
Is there a good replacement for wordpress comments? That's the one thing holding me back from porting at the moment.
karthikeyankc8 days ago
I had the same itch when I ported my personal blog from WordPress to Astro. I built a fully customisable self-hosted comment system called Discuss. It's got a dashboard and tokenized UI customisation. Pretty light weight too. It's available here - https://github.com/karthikeyankc/discuss . Do give it a spin or fork it. Would love to hear your feedback.
iLoveOncall8 days ago
I think you can render Disqus on static websites, but Disqus is its own piece of crap so not sure you'd want to.
foco_tubi8 days ago
We are in a big migration project at work and one of the goals is to rewrite all 30 or so WordPress sites into Astro. It’s so much fun to cut out all the blackbox plugins with paid features and cruft, and just have something work as I intended. I’m stoked.
cyphar8 days ago
This kind of bug pathology is incredibly common in all sorts of programs and is the reason (disclaimer: self-plug) I wrote libpathrs[1].

Sadly, almost all language standard libraries do not provide the right abstractions for dealing with files (the primary focus is on global paths as opposed to scoped paths or file descriptors / file handles) so it's little surprise bugs like these just keep popping up every few weeks.

To eliminate these from your codebase you need to rethink and really focus on being aware of how you deal with files. If the program you're writing has root privileges then you need to be more careful about misdirected writes to /proc or other pseudofilesystems.

[1]: https://github.com/cyphar/libpathrs

Read the full thread on Hacker News →

Related stories