WordPress 7.1.2 Patches an Unauthenticated File Inclusion Flaw That Can Lead to Code Execution

WordPress 7.1.2 fixes an unauthenticated local file inclusion flaw in get_page_template(). The bug lets a visitor with no login force WordPress to include a local .php file from outside the active theme directories. The advisory was published on Sept. 22, 2026. WordPress Security Advisory
No authentication is required. The caller has enough control over template path resolution to step outside the intended theme folder and reach any local .php file that the web server account can read. On its own, that is file inclusion. It becomes remote code execution, where an attacker can run commands on the server, only when two additional preconditions line up.
The first is the theme precondition. Exploitation requires the active child theme or the active parent theme to contain a top-level directory whose name starts with page-, such as page-templates. The check looks at directory names only, not at whether a template is registered or assigned to a page. If no such directory exists in the active theme chain, the attacker-controlled path does not resolve.
Two older bundled themes meet that condition: Twenty Twelve and Twenty Fourteen. Three widely used third-party themes are listed as affected examples: Neve, Hestia and Sydney. The list is illustrative, not complete. Any child or parent theme with a matching top-level page- directory exposes the same path.
The second is the server precondition. The chosen .php file must exist on the server and be readable by the web server user. The documented route to code execution uses pearcmd.php with the long-known PEAR-to-RCE technique when register_argc_argv is set to On. That PHP setting, which controls whether web request values are also made available as command-line arguments in $argv, lets query string values feed argument injection into the PEAR command dispatcher and then run code in the web server context.
That setting is not rare. The official PHP image for Docker meets the register_argc_argv precondition. Default cPanel configuration also meets it when PHP prior to 8.5 is in use. Operators on either stack face a satisfiable server side unless they have explicitly hardened it. Other stacks with register_argc_argv enabled and a reachable pearcmd.php carry the same exposure.
The fix ships in WordPress 7.1.2 and has been backported to all supported branches back to 4.7. The flaw, tracked as GHSA-7hp8-65ch-5whp, was discovered and responsibly disclosed by Robert Ressl.
The broader context here is that severity is conditional rather than universal. Themes without a matching directory do not expose the include path. Runtimes with register_argc_argv off and no reachable PEAR file blunt the chain to code execution. That makes inventory the first task, to identify which sites run a vulnerable child or parent theme while checking PHP settings and image baselines in parallel.
In my view, the sensible order is patch first, triage second. The backports to 4.7 remove the need to rush a major version upgrade to close the flaw. For sites that cannot patch at once, removing or renaming an unused page- directory is not a supported fix, and editing theme code carries regression risk. Containment sits better with update scheduling and runtime hygiene around register_argc_argv, Docker base images and shared hosting defaults. Over the longer arc, template loading in PHP still carries more execution power than it appears to, and closing that gap leaves site owners with more reliable ground to build on.


