1 article with this tag
Unauthenticated local file inclusion in WordPress core 4.7–7.1.1 (CWE-98), leading to RCE when theme and server conditions line up. Fixed 22 September (7.1.2 and every branch back to 4.7); CISA added it to KEV on 25 September. This site's view: an EPSS of 3% does not matter once it is in KEV. Update, and also turn off PHP's register_argc_argv to cut the server-side half of the chain.