upvote
I wonder if they'll add a `locate_template_safe()` function to "fix" it. :D
reply
It's a mystery how this exploit was found.

/sarc

reply
Ahahah I remember to have patched themes for clients by hand, years ago. A different time, where a core team would for whatever reason leave security holes around to be sure you need three frameworks around their pile of dung code.
reply