A critical security vulnerability has been disclosed in WordPress, affecting the get_page_template() function used for page-template resolution. The flaw could allow an unauthenticated attacker to achieve remote code execution (RCE) under limited circumstances, according to the project's advisory.

The vulnerability is rated as critical, but its exploitation is not universal. The attack requires specific conditions that are not present in a default WordPress installation, meaning most standard deployments are not directly at risk.

WordPress has provided updates for the most recent branch of the software, as well as backports of the fix for older branches. ClassicPress, a fork of WordPress, is also affected by the same vulnerability. At the time of reporting, ClassicPress had not yet released a security update addressing the flaw.

Site administrators are strongly advised to check their installed version and apply the relevant security update promptly. Given the critical nature of the vulnerability, any installation that could potentially meet the exploitation conditions should be treated as a priority.


WordPress被披露存在一個嚴重安全漏洞,影響用於頁面範本解析的get_page_template()函數。據該專案的安全公告指,該缺陷可能在有限情況下允許未經認證的攻擊者實現遠端代碼執行(RCE)。

該漏洞被評估為嚴重,但其利用並非普遍適用。攻擊需要特定條件,而這些條件並不存在於WordPress的預設安裝中,意味著大多數標準部署並非直接受風險影響。

WordPress已為其軟件的最新分支提供更新,並將修補程式回溯移植至較舊的分支。作為WordPress分支的ClassicPress同樣受到此漏洞影響。在報導時,ClassicPress尚未發布針對此缺陷的安全更新。

強烈建議網站管理員立即檢查其已安裝的版本,並及時套用相關安全更新。鑒於此漏洞的嚴重性,任何可能符合利用條件的安裝均應優先處理。

新聞來源 / Original News Source