CVE-2026-87902
An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the active theme directories. If relevant pre-conditions for both the server and the active theme are met, this can lead to RCE.
- Published Sep 22, 2026
- CVSS 8.1 high
- 46.1% chance of exploitation in the next 30 days (EPSS)
- In CISA's Known Exploited Vulnerabilities catalog
- Public exploit code is available
Affected software
In the news
- A Vulnerability in WordPress Could Allow for Remote Code Execution CIS MS-ISAC ·
- ⚡ Weekly Recap: $387M Crypto Hack, Citrix Exploits, AI Agents Go Off-Script, and More Threats The Hacker News ·
- CISA Adds One Known Exploited Vulnerability to Catalog CISA ·
- Attackers Exploit WordPress CVE-2026-87902 Within Hours of Disclosure The Hacker News ·
- WordPress security advisory (AV26-952) – Update 1 Canadian Centre for Cyber Security ·
- Vulnerability in WordPress CERT-FR ·
- WordPress Issues Patch for Critical Flaw That Can Enable Code Execution on Some Servers The Hacker News ·