Executive brief
WordPress Core, which powers millions of websites worldwide, contains a vulnerability that allows unauthenticated attackers to include and execute arbitrary PHP files from the server. An attacker can exploit this to gain control of the entire website and underlying server, potentially leading to data theft, defacement, or use as a launch point for further attacks.
Technical details
WordPress Core contains a remote file inclusion (RFI) vulnerability in page-template resolution logic. The vulnerability allows unauthenticated attackers to manipulate template resolution to include arbitrary readable PHP files from outside the active theme directories. The attack is network-accessible and requires no authentication or user interaction. Successful exploitation leads to remote code execution with the privileges of the web server process. The vulnerability has been actively exploited in the wild as of September 2026.
Affected products
- WordPress WordPress Core
Timeline
- 2026-09-25: disclosed
- 2026-09-25: exploited