An unauthenticated attacker can trick WordPress’s page-template lookup into loading a readable PHP file from outside the active theme, potentially leading to remote code execution on the server.