‹ BackHN Continuity

Thread

WordPress: Unauthenticated path traversal leading to conditional RCE

240 points · 132 comments · vntok

  1. vntok · · focus · HN ↗
    Ironically, this 9 years old comment on the official documentation page of one of the affected functions perfectly describes both the nature and remediation of this major security flaw:

    > Paul Ryan 9 years ago

    > Note that locate_template() does not prevent directory traversal attacks, so if you’re passing a user-provided template name to the function, be sure to verify that it’s from one of the three appropriate locations (active theme directory, parent theme directory, or /wp-includes/theme-compat/ directory).

    <a href="https:&#x2F;&#x2F;developer.wordpress.org&#x2F;reference&#x2F;functions&#x2F;locate_template&#x2F;" rel="nofollow">https:&#x2F;&#x2F;developer.wordpress.org&#x2F;reference&#x2F;functions&#x2F;locate_t...

    1. IshKebab · · focus · HN ↗
      I wonder if they&#x27;ll add a `locate_template_safe()` function to &quot;fix&quot; it. :D
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.