CVE-2026-87902
CVSS Score
8.1
EPSS Score
0.0%
EPSS Percentile
0th
An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the active theme directories. If relevant pre-conditions for both the server and the active theme are met, this can lead to RCE.
| CWE | CWE-98 |
| Vendor | wordpress |
| Product | wordpress |
| Ecosystems | |
| Industries | WebMedia |
| Published | Sep 22, 2026 |
| Last Updated | Sep 22, 2026 |
Stay Ahead of the Next One
Get instant alerts for wordpress wordpress
Be the first to know when new high vulnerabilities affecting wordpress wordpress are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
WordPress / WordPress
0 < 7.1.2
References
Credits
Robert (ressl)