{
  "id": 9349899,
  "title": "Critical WordPress RCE vulnerability announced",
  "url": "https://urgent.news/2026/09/23/critical-wordpress-rce-vulnerability-announced",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-23T13:55:40.000Z",
  "source": {
    "name": "LWN",
    "slug": "lwn",
    "url": "https://lwn.net/Articles/1096195/"
  },
  "original_language": "en",
  "account": null,
  "summary": "A critical vulnerability has been discovered in WordPress 's get_page_template() function for page-template resolution that could allow remote-code execution (RCE) by an unauthenticated attacker, in some limited circumstances. The project has provided an update for the most recent branch of WordPress, as well as backports of the fix for branches back to 4.7 . See the vulnerability report for the…",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}