Critical RCE in template resolution patched
WordPress 7.1.2 fixes a critical severity vulnerability where an unauthenticated attacker can, under certain conditions, make page template resolution include a chosen readable local PHP file outside the active theme directories, potentially leading to remote code execution. The fix is being backported to all branches eligible for security fixes, currently through 4.7.
