Remix.run Logo
vntok a day ago

Ironically, this 9 years old comment on the official documentation page of one of the affected functions perfectly describes both the nature and remediation of this major security flaw:

> Paul Ryan 9 years ago

> Note that locate_template() does not prevent directory traversal attacks, so if you’re passing a user-provided template name to the function, be sure to verify that it’s from one of the three appropriate locations (active theme directory, parent theme directory, or /wp-includes/theme-compat/ directory).

https://developer.wordpress.org/reference/functions/locate_t...

erichocean a day ago | parent | next [-]

It's a mystery how this exploit was found.

/sarc

foul a day ago | parent | prev | next [-]

Ahahah I remember to have patched themes for clients by hand, years ago. A different time, where a core team would for whatever reason leave security holes around to be sure you need three frameworks around their pile of dung code.

IshKebab a day ago | parent | prev [-]

I wonder if they'll add a `locate_template_safe()` function to "fix" it. :D