Jesus. I don't think WP is nice to use, but people are saying WP is crap because someone else made pearcmd.php that allows you to run arbitrary commands, and then a third someone else included that in the default PHP docker image. In this case all PHP CMS's are a directory traversal bug away from this CVE.
Indeed. Then again, it's on WordPress not to have directory traversal flaws in their core functions...
- especially the functions that are explicitely exposed to be used on front-facing interfaces (ie: templating functions).
- and especially when the security flaw in question was not only raised 9 years ago but described in details on the official documentation page of the affected function