Authenticated Path Traversal in WP REST Templates Controller
Software
WordPress
Affected versions
7.1.0 - 7.1
7.0.0 - 7.0.4
6.9.0 - 6.9.7
6.8.0 - 6.8.8
6.7.0 - 6.7.7
6.6.0 - 6.6.7
6.5.0 - 6.5.10
6.4.0 - 6.4.10
6.3.0 - 6.3.10
6.2.0 - 6.2.11
6.1.0 - 6.1.12
6.0.0 - 6.0.14
5.9.0 - 5.9.16
Patched versions
7.1.1
7.0.5
6.9.8
6.8.9
6.7.8
6.6.8
6.5.11
6.4.11
6.3.11
6.2.12
6.1.13
6.0.15
5.9.17
The REST templates endpoint accepts template IDs whose slug regex can result in an unbound filesystem path. An authenticated Author can read any .html file on the server.
WordPress 7.1.1 has been released containing a fix for the vulnerability, and as a courtesy to users on older branches the fix has been backported to all branches back to 5.9.
Discovered and responsibly disclosed by Anthropic.