CVE-2026-87902
HIGHAn unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the active theme directories. If relevant pre-conditions for both the server and the active theme are met, this can lead to RCE.
Published: 9/22/2026Modified: 9/28/2026
References (3)
https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-7hp8-65ch-5whpVendor Advisoryhttps://patchstack.com/articles/cve-2026-87902-attackers-started-probing-wordpress-sites-hours-after-the-patch/Third Party Advisoryhttps://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-87902US Government Resource