[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"branding":3,"analytics":7,"article-wordpress-discloses-path-traversal-flaw-with-rce-potential":10,"sections":40},{"siteName":4,"siteTagline":5,"publisherName":4,"contactEmail":6},"The Revision","Tech news, decoded.","editor@therevision.news",{"gaMeasurementId":8,"adsenseClientId":9},"G-ZW2MV82GYR","ca-pub-8533917693782264",{"article":11},{"id":12,"slug":13,"title":14,"dek":15,"body_md":16,"tags_json":17,"published_at":18,"created_at":19,"updated_at":20,"status":21,"review_note":22,"review_notes":23,"image_url":22,"persona_id":22,"persona_name":22,"section":30,"tags":31,"sources":35,"feedback":39,"feedback_at":22,"cost_usd":39,"total_tokens":39},7233,"wordpress-discloses-path-traversal-flaw-with-rce-potential","WordPress Discloses Path Traversal Flaw With RCE Potential","A new WordPress core advisory details an unauthenticated path traversal bug that can escalate to remote code execution under certain conditions.","WordPress has published a core security advisory for an unauthenticated path traversal bug that can lead to remote code execution.\n\nThe advisory, GHSA-7hp8-65ch-5whp, was filed against the wordpress-develop repository on GitHub. It describes a flaw that lets an attacker who isn't logged in reach files outside the folder the application intends to expose. Under certain server conditions, that traversal can be escalated into remote code execution, which is why the advisory's own title calls it \"conditional.\" The bug lives in WordPress core itself, not in a third-party plugin or theme.\n\nThat distinction is the story here. Most WordPress security bulletins come out of the plugin and theme ecosystem, where a flaw only affects the sites that installed the vulnerable extension. A core-level bug is different: it potentially touches every WordPress install running the affected code, no plugin choices required.\n\nCore advisories are rarer than plugin ones precisely because WordPress's core codebase gets far more scrutiny. That rarity is exactly why this one is worth watching rather than filing away as routine patch-Tuesday noise.","[\"wordpress\",\"security\",\"vulnerability\",\"open-source\"]","2026-09-22T16:33:45.000Z","2026-09-22T17:38:50.803Z","2026-09-22T17:38:56.691Z","published",null,[24],{"id":25,"reviewer":26,"round":27,"reason":28,"status":29},"editor-r1","editor",1,"Drop the meta-commentary noting what the advisory 'does not spell out... in what's public so far' (CVE number, version range, patch status) — this is the same placeholder-style hedge as 'the report doesn't specify' and should be cut or replaced with confirmed facts only.","resolved","security",[32,30,33,34],"wordpress","vulnerability","open-source",[36],{"name":37,"url":38},"Hacker News","https:\u002F\u002Fgithub.com\u002FWordPress\u002Fwordpress-develop\u002Fsecurity\u002Fadvisories\u002FGHSA-7hp8-65ch-5whp",0,{"sections":41},[42,47,51,56,61,66,71,75,80,85,90,95,100,105],{"name":43,"slug":44,"count":45,"latest_published_at":46},"AI","ai",4195,"2026-09-22T19:28:23.000Z",{"name":48,"slug":30,"count":49,"latest_published_at":50},"Security",702,"2026-09-22T21:01:05.000Z",{"name":52,"slug":53,"count":54,"latest_published_at":55},"Policy","policy",366,"2026-09-22T18:04:41.000Z",{"name":57,"slug":58,"count":59,"latest_published_at":60},"Deals","deals",200,"2026-09-22T19:28:55.000Z",{"name":62,"slug":63,"count":64,"latest_published_at":65},"Hardware","hardware",167,"2026-09-22T20:00:00.000Z",{"name":67,"slug":68,"count":69,"latest_published_at":70},"Science","science",131,"2026-09-22T16:26:30.000Z",{"name":72,"slug":73,"count":74,"latest_published_at":65},"Consumer Tech","consumer-tech",110,{"name":76,"slug":77,"count":78,"latest_published_at":79},"Software","software",79,"2026-09-22T19:44:31.000Z",{"name":81,"slug":82,"count":83,"latest_published_at":84},"Dev Tools","dev-tools",78,"2026-09-18T04:00:00.000Z",{"name":86,"slug":87,"count":88,"latest_published_at":89},"Startups","startups",63,"2026-09-22T21:24:11.000Z",{"name":91,"slug":92,"count":93,"latest_published_at":94},"Gaming","gaming",45,"2026-09-22T15:35:06.000Z",{"name":96,"slug":97,"count":98,"latest_published_at":99},"General","general",43,"2026-09-21T23:48:56.000Z",{"name":101,"slug":102,"count":103,"latest_published_at":104},"Reviews","reviews",27,"2026-09-22T13:00:00.000Z",{"name":106,"slug":107,"count":108,"latest_published_at":109},"How-To","how-to",6,"2026-06-16T09:00:00.000Z"]