๐Ÿ” CVE Alert

CVE-2026-87902

HIGH 8.1
CVSS Score
8.1
EPSS Score
0.0%
EPSS Percentile
0th

An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the active theme directories. If relevant pre-conditions for both the server and the active theme are met, this can lead to RCE.

CWE CWE-98
Vendor wordpress
Product wordpress
Ecosystems
Industries
WebMedia
Published Sep 22, 2026
Last Updated Sep 22, 2026
Stay Ahead of the Next One

Get instant alerts for wordpress wordpress

Be the first to know when new high vulnerabilities affecting wordpress wordpress are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

WordPress / WordPress
0 < 7.1.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-7hp8-65ch-5whp

Credits

Robert (ressl)