CVE-2026-87902

HIGH

An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the active theme directories. If relevant pre-conditions for both the server and the active theme are met, this can lead to RCE.

CVSS v3.1 Score

8.1
HIGH
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Complexity
HIGH
Privileges
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH
Published: 9/22/2026Modified: 9/28/2026

Related Intelligence (5)

HIGHVulnerability

CISA KEV: WordPress Core — WordPress Core Remote File Inclusion Vulnerability

WordPress Core contains a remote file inclusion vulnerability which could allow an unauthenticated attacker to make page-template resolution include a chosen readable local `.php` file outside the active theme directories, leading to remote code execution.

CVE-2026-87902WordPress Core
CISA KEV
CRITICALApt

WordPress patches a critical severity security vulnerability

WordPress has patched what it described as a critical severity security vulnerability that would allow an unauthenticated attacker full remote code execution (RCE) capabilities. There have already been reports of attacks in the wild. Given its popularity, WordPress has frequently been under attack , and patched another maximum severity bug allowing RCE in July. WordPress said the current hole, tra

CVE-2026-87902
CSO Online
CRITICALVulnerability

Critical WordPress Vulnerability Exploited Immediately After Disclosure

Tracked as CVE-2026-87902, the path traversal flaw allows remote, unauthenticated attackers to execute arbitrary code. The post Critical WordPress Vulnerability Exploited Immediately After Disclosure appeared first on SecurityWeek .

CVE-2026-87902
SecurityWeek
CRITICALVulnerability

Attackers Exploit WordPress CVE-2026-87902 Within Hours of Disclosure

Threat actors have begun to actively exploit a critical security flaw in WordPress within hours of public disclosure. The vulnerability in question is CVE-2026-87902 (CVSS score: 9.2), which could allow an unauthenticated attacker to obtain remote code execution (RCE). "An unauthenticated attacker can make get_page_template() page-template resolution include a chosen readable local .php file

CVE-2026-87902
The Hacker News
MEDIUMVulnerability

CVE-2026-87902: Attackers Started Probing WordPress Sites Hours After the Patch

[object Object]

CVE-2026-87902
r/blueteamsec

References (3)