‹ BackHN Continuity

Thread

WordPress: Unauthenticated path traversal leading to conditional RCE

240 points · 132 comments · vntok

  1. tptacek · · focus · HN ↗
    These CVSS scores don't mean anything and it would be better for everyone if they stopped showing up in headlines. This is a somewhat situational Wordpress RCE that impacts only a couple themes.
    1. vntok · · focus · HN ↗
      > This is a somewhat situational Wordpress RCE that impacts only a couple themes. reply

      That is dangerously incorrect, a whole lot of themes are vulnerable. The main pre-condition, "presence of a top-level directory named 'page-xxx' like 'page-templates' in the theme's directory" is actually an official recommendation in the WordPress documentation.

      See here: <a href="https:&#x2F;&#x2F;developer.wordpress.org&#x2F;themes&#x2F;classic-themes&#x2F;templates&#x2F;page-template-files&#x2F;" rel="nofollow">https:&#x2F;&#x2F;developer.wordpress.org&#x2F;themes&#x2F;classic-themes&#x2F;templa...

      &gt; As discussed in Organizing Theme Files, WordPress can recognize page templates stored in the theme’s root folder or in a first-level subdirectory of the theme folder. *The page-templates&#x2F; folder is a common convention* for organizing global page templates, but it is not required. Page templates can also be stored in other first-level subdirectories, such as templates&#x2F; or page_templates&#x2F;.

      1. dawnerd · · focus · HN ↗
        Yeah not sure why you’re being downvoted when the built in themes are vulnerable as is the default docker image pre php8.5 which a lot of people use as a base and I bet a lot of hosting providers use as well behind the scenes.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.