Path traversal in WordPress - #VU151462
Published: September 20, 2026
Vulnerability details
The vulnerability allows a remote user to read arbitrary .html files on the server.
The vulnerability exists due to improper path validation in the WP REST Templates Controller when processing template IDs. A remote user can submit a crafted template ID to read arbitrary .html files on the server.
Exploitation requires Author permissions.