CVE-2017-14722: WordPress

High severity, CVSS 7.5. EPSS: 7.1% chance of exploitation in the next 30 days.

Before version 4.8.2, WordPress allowed a Directory Traversal attack in the Customizer component via a crafted theme filename.

Affected products

  • WordPress WordPress: version 4.7 only; version 4.7.1 only; version 4.7.2 only; version 4.7.3 only; version 4.7.4 only; version 4.7.5 only; …

Published 2017-09-23. Last modified 2026-06-17.