WordPress: Unauthenticated path traversal leading to conditional RCE
Thread
Unofficial Hacker News client; not affiliated with Y Combinator.
WordPress: Unauthenticated path traversal leading to conditional RCE
Unofficial Hacker News client; not affiliated with Y Combinator.
random_savv · · focus · HN ↗
vntok · · focus · HN ↗
<a href="https://app.opencve.io/cve/CVE-2026-89259" rel="nofollow">https://app.opencve.io/cve/CVE-2026-89259
<a href="https://app.opencve.io/cve/CVE-2026-89258" rel="nofollow">https://app.opencve.io/cve/CVE-2026-89258
benregenspan · · focus · HN ↗
For the Wordpress RCE (nominally CVSS 9.2), it looks like many standard deployments of WordPress would be affected, barring extra mitigations. But in the case of these Hugo ones (9.3), it looks like very specific circumstances (anti-mitigations, if you will) are needed. E.g. running arbitrary builds of untrusted user content without a sandbox; running it in a GitHub workflow against PRs from untrusted contributors, etc.