PSA: Critical Unauthenticated Path Traversal Vulnerability Patched in WordPress Core
WordPress has released security updates for a critical unauthenticated path traversal vulnerability that can lead to local PHP file inclusion and, on affected server and theme configurations, remote code execution. Site owners should update WordPress Core immediately.