frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Open in hackernews

WordPress: Unauthenticated path traversal leading to conditional RCE

https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-7hp8-65ch-5whp
21•vntok•50m ago

Comments

system2•26m ago
pearcmd.php must exist, and register_argc_argv must be on, not common with hosting providers. But I am assuming the other themes and meeting conditions possibly affect a lot of WordPress sites.
dofm•8m ago
As the article points out, one issue is that the official Docker container for PHP has this configuration.

However at least in principle all of the affected versions [0] could be automatically updated. Not sure if they have set it to auto-update as far back as 4.7 though.

[0] except 4.9.3 which has a bug in its automatic update mechanism.

foul•4m ago
pearcmd and register_argc_argv are just examples. get_page_template was unsanitized in some themes, that's the flaw, you could then combine it with one of a million unauthorized file upload in wordpress plugins to try and eval code. An attacker would like to use upload + this chain of requires (instead of just uploading a php) because of hardened configuration and the pwn can go unnoticed in the logs.

Also, with pearcmd (if you can get to that, there's no open_basedir) and containers a novice sysadmin will publish insecure sites.

tptacek•22m ago
These CVSS scores don't mean anything and it would be better for everyone if they stopped showing up in headlines. This is a somewhat situational Wordpress RCE that impacts only a couple themes.
paulez•11m ago
This score specifically means that given some specific conditions, anyone can execute code over the network on a vulnerable WordPress setup. Is this not true?
tptacek•4m ago
I'm not saying that the vulnerability isn't severe or important to people running Wordpress, only that CVSS scores are literally a Ouija Board that can come out to whatever the user wants them to.
vntok•10m ago
> This is a somewhat situational Wordpress RCE that impacts only a couple themes. reply

That is dangerously incorrect, a whole lot of themes are vulnerable. The main pre-condition, "presence of a top-level directory named 'page-xxx' like 'page-templates' in the theme's directory" is actually an official recommendation in the WordPress documentation.

See here: https://developer.wordpress.org/themes/classic-themes/templa...

> As discussed in Organizing Theme Files, WordPress can recognize page templates stored in the theme’s root folder or in a first-level subdirectory of the theme folder. *The page-templates/ folder is a common convention* for organizing global page templates, but it is not required. Page templates can also be stored in other first-level subdirectories, such as templates/ or page_templates/.

dofm
whycome•13m ago
hmm, this may be why i just saw an unexpected update to a very old theme.
vntok•6m ago
Ironically, this 9 years old comment on the official documentation page of one of the affected functions perfectly describes both the nature and remediation of this major security flaw:

> Paul Ryan 9 years ago

> Note that locate_template() does not prevent directory traversal attacks, so if you’re passing a user-provided template name to the function, be sure to verify that it’s from one of the three appropriate locations (active theme directory, parent theme directory, or /wp-includes/theme-compat/ directory).

https://developer.wordpress.org/reference/functions/locate_t...

•
3m ago
Not sure if it’s a couple. Devs routinely make heavily edited copies of the core themes so there will be many, many unpublished themes that use the “page-“ prefix for templates; it was (is?) a reasonably common convention.

(No particular disagreement with the rest of your comment though)

DeepSeek injects 50% more bugs when prompted with Chinese political triggers

https://venturebeat.com/security/deepseek-injects-50-more-security-bugs-when-prompted-with-chines...
1•charukiewicz•14s ago•0 comments

NASA Discovery Reveals Complex Water Systems on Early Mars

https://www.jpl.nasa.gov/news/nasa-discovery-reveals-complex-water-systems-on-early-mars/
1•gmays•21s ago•0 comments

TinyJev -Tiny Jev-style decision model that runs offline

https://github.com/ankit-aglawe/tinyjev
1•aglaweankit•1m ago•0 comments

Are the Government's Conversations with AI Accessible Under Public Records Laws? [pdf]

https://reason.com/wp-content/uploads/2026/09/Are-the-Goverments-AI-Conversations-Accessible.pdf
2•compiler-guy•1m ago•0 comments

German court rules Meta liable for scam ads on Facebook and Instagram

https://thenextweb.com/news/meta-scam-ads-ruling-germany-frankfurt-court
3•buzer•3m ago•2 comments

Priorities and principles for effective third party assessments

https://openai.com/index/priorities-principles-third-party-assessments/
1•samaysharma•4m ago•0 comments

Scaling Discovery Through Test-Time Communication

https://arxiv.org/abs/2609.21032
1•marojejian•4m ago•0 comments

Kclaw is a K8s-based IT-managed, multi-tenant AI assistant platform for teams

https://github.com/info-struct/kclaw
2•Ryan-info-struc•4m ago•1 comments

We put Jev in production against a cross-encoder. Here are the numbers

https://getunblocked.com/blog/jev-in-production-vs-cross-encoder/
2•dennispi•5m ago•0 comments

Show HN: A facial analysis tool with scores and geometry measurements

https://pslscore.org/
1•amaz89•5m ago•0 comments

Twinkleplop – plop some twinkle in your code (ultrafast syntax highlighting)

https://twinkleplop.pngwn.at/
1•kevinak•8m ago•0 comments

Grok 4.7 Scores 46 on AI Intelligence Index, Puts SpaceXAI in Top 4 Labs

https://artificialanalysis.ai/articles/benchmarking-grok-4-7
2•wertyk•11m ago•0 comments

There's a high chance of devices being sold with GrapheneOS preinstalled in 2027

https://grapheneos.social/@GrapheneOS/117299954135808210
3•Cider9986•11m ago•1 comments

Moving from cash to credit cards, PayPal, etc. is an ongoing privacy disaster

https://grapheneos.social/@GrapheneOS/117249893761790371
11•Cider9986•12m ago•1 comments

In 200-Page Report, Cornell Confronts the Crisis in American Higher Education

https://www.wsj.com/us-news/education/cornell-report-higher-education-18d136fd
2•LostMyLogin•13m ago•0 comments

Shall We Repeal the Laws of Economics – Part III

https://www.oaktreecapital.com/insights/memo/shall-we-repeal-the-laws-of-economics---part-iii
2•ourmandave•13m ago•0 comments

Alzheimer's Is No Longer an Untreatable Disease

https://www.sciencealert.com/alzheimers-is-no-longer-an-untreatable-disease-major-report-conclude...
3•gmays•13m ago•0 comments

A golden opportunity: Seattle's surveillance pricing ban

https://thenexusofprivacy.net/a-golden-opportunity-in-seattle/
1•jdp23•15m ago•0 comments

ASML Executive Says It Has No Sales in Europe

https://www.bloomberg.com/news/articles/2026-09-22/asml-executive-says-europe-s-biggest-firm-has-...
4•alephnerd•15m ago•0 comments

Bugcrowd is currently fundamentally broken

https://blog.leonbecker.de/bugcrowd-is-currently-fundamentally-broken/
1•rowbin•16m ago•0 comments

Why is social media so humourless?

https://www.baldurbjarnason.com/2026/03-why-is-social-media-so-humourless/
1•speckx•16m ago•0 comments

Ask HN: How do your teams share and distribute agent skills?

2•juanviera23•16m ago•0 comments

What drives BigQuery costs, and what doesn't

https://www.erathos.com/en/blog/bigquery-cost-optimization
2•gpaulbagetti•17m ago•1 comments

Should TypeScript support runtime types instead of relying on Zod?

https://twitter.com/mykhailen/status/2102442831314842034
2•emykhailenko•17m ago•1 comments

We are the last generation of human psychiatrists

https://www.cambridge.org/core/journals/the-british-journal-of-psychiatry/article/we-are-the-last...
1•TMWNN•18m ago•0 comments

Grok bot is now in Tesla

https://twitter.com/elonmusk/status/2102439262507725294
6•vertigoruntime•18m ago•1 comments

Implementing the Camera Mechanic from Viewfinder

https://ishamf.dev/p/implementing-viewfinder-mechanic/
1•ifz•20m ago•0 comments

Show HN: Ttmux, a Modern and Fast Tmux

https://github.com/statico/ttmux
1•statico•20m ago•1 comments

Anthropic launches Claude Opus 5.5 with stricter safeguards for cybersecurity

https://www.theverge.com/ai-artificial-intelligence/998868/anthropic-claude-opus-5-5-cybersecurity
1•pdyc•20m ago•0 comments

Claude Opus 5.5 for code review: More catches, different misses

https://www.coderabbit.ai/blog/opus-5-5-model-review
1•Leynos•20m ago•0 comments