A WordPress vulnerability scored 9.2/10 is present in all versions since 2016
WordPress / wordpress-develop Public Notifications You must be signed in to change notification settings Fork 3.7k Star 3.4k Code Pull requests 3.5k Actions Security and quality 43 Insights Additional navigation options Code Pull requests Actions Security and quality Insights wordpress-develop Security Advisories GHSA-7hp8-65ch-5whp Unauthenticated path traversal in page-template resolution leading to conditional RCE Critical johnbillion published GHSA-7hp8-65ch-5whp Sep 22, 2026 Software WordPress Affected versions 7.1.0 - 7.1.1 7.0.0 - 7.0.5 6.9.0 - 6.9.8 6.8.0 - 6.8.9 6.7.0 - 6.7.8 6.6.0 - 6.6.8 6.5.0 - 6.5.11 6.4.0 - 6.4.11 6.3.0 - 6.3.11 6.2.0 - 6.2.12 6.1.0 - 6.1.13 6.0.0 - 6.0.15 5.9.0 - 5.9.17 5.8.0 - 5.8.16 5.7.0 - 5.7.18 5.6.0 - 5.6.20 5.5.0 - 5.5.21 5.4.0 - 5.4.22 5.3.0 - 5.3.24 5.2.0…
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in