A vulnerability has been discovered in WordPress that could allow arbitrary code on the web server. WordPress is a free, open-source content management system (CMS) that allows you to build and manage websites without needing to write code. Successful exploitation allows an unauthenticated attacker to manipulate the page-template resolution logic to execute local PHP files outside the active theme directory, potentially leading to Remote Code Execution (RCE) under specific conditions.