The Page Template Reached Outside the Theme
CISA says attackers are exploiting a critical WordPress core flaw that lets an unauthenticated request steer template resolution to a readable local PHP file and, on vulnerable stacks, reach remote code execution.