→ برگشت به فید آسیب‌پذیری‌ها CVE-2026-87902 · wordpress

فراخوانی ناامن فایل‌های محلی (LFI) در هسته وردپرس

بالا core CVSS 8.1

WordPress Core is vulnerable to Local File Inclusion via the locate_template() function in various versions up to, and including, 7.1.1. The function resolved a caller-supplied template name against the theme directories without verifying the result stayed within them, so a template name containing '..' could resolve to a readable PHP file outside the active theme and be included. The core-reachable vector is get_page_template(), which builds page-{$pagename}.php from the URL-derived, url-decoded 'pagename' query variable. This makes it possible for unauthenticated attackers to make page-template resolution include a chosen readable local .php file outside the theme directories, which under certain conditions can lead to remote code execution. Exploitation requires (1) the active parent or child theme to contain a top-level directory whose name begins with 'page-' (e.g. 'page-templates' in Twenty Twelve, Twenty Fourteen, Neve, Hestia, Sydney), and (2) a readable .php target on the server accessible to the web-server account (e.g. pearcmd.php with register_argc_argv=On, as in the official PHP Docker image and default cPanel setups on PHP < 8.5), which yields RCE.

نسخه‌های تحت تأثیر

>= 4.7 & <= 4.7.36, >= 4.8 & <= 4.8.31, >= 4.9 & <= 4.9.32, >= 5.0 & <= 5.0.28, >= 5.1 & <= 5.1.25, >= 5.2 & <= 5.2.27, >= 5.3 & <= 5.3.24, >= 5.4 & <= 5.4.22, >= 5.5 & <= 5.5.21, >= 5.6 & <= 5.6.20, >= 5.7 & <= 5.7.18, >= 5.8 & <= 5.8.16, >= 5.9 & <= 5.9.17, >= 6.0 & <= 6.0.15, >= 6.1 & <= 6.1.13, >= 6.2 & <= 6.2.12, >= 6.3 & <= 6.3.11, >= 6.4 & <= 6.4.11, >= 6.5 & <= 6.5.11, >= 6.6 & <= 6.6.8, >= 6.7 & <= 6.7.8, >= 6.8 & <= 6.8.9, >= 6.9 & <= 6.9.8, >= 7.0 & <= 7.0.5, >= 7.1 & <= 7.1.1

راهنمای اقدام و رفع مشکل (Remediation)

  • ۱. پشتیبان‌گیری: قبل از اعمال هرگونه تغییر، یک بکاپ کامل از پایگاه داده و فایل‌های سایت تهیه کنید.
  • ۲. به‌روزرسانی سریع: افزونه یا هسته wordpress را بلافاصله به آخرین نسخه ارائه‌شده ارتقا دهید.
  • ۳. فایروال و مانیتورینگ: در صورت عدم امکان آپدیت فوری، رول‌های امنیتی WAF را فعال کرده و لاگ‌های وب‌سرور را پایش نمایید.