CVE-2026-87902

Published Sep 22, 2026

Last updated 2 hours ago

Overview

Description
An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the active theme directories. If relevant pre-conditions for both the server and the active theme are met, this can lead to RCE.
Source
support@hackerone.com
NVD status
Undergoing Analysis

Risk scores

CVSS 3.1

Type
Secondary
Base score
8.1
Impact score
5.9
Exploitability score
2.2
Vector string
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
HIGH

Weaknesses

support@hackerone.com
CWE-98

Social media

Hype score
Not currently trending
  1. 6 new OPEN, 7 new PRO (6 + 1) CVE-2026-17633 (IBM Langflow RCE), CVE-2026-87902 (Wordpress Core Template Path Traversal), CVE-2026-42779 (Apache MINA Allowlist Bypass RCE), TA569, and more. https://t.co/rV4vsQj0Kf

    @ET_Labs

    25 Sept 2026

    125 Impressions

    2 Retweets

    0 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  2. WordPress CVE-2026-87902 is being exploited in the wild. Attackers are exploiting a critical WordPress flaw within hours of disclosure: - CVE-2026-87902, CVSS 9.2 - Unauthenticated RCE via path traversal - Active exploitation confirmed by The Hacker News Patch immediately if

    @so_sthbryan

    25 Sept 2026

    43 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  3. Attackers Exploit WordPress CVE-2026-87902 Within Hours of Disclosure(WordPressのCVE-2026-87902、公開から数時間で攻撃者が悪用) #TheHackerNews (Sep 24) https://t.co/eBUJePv4NO

    @foxbook

    25 Sept 2026

    337 Impressions

    0 Retweets

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. CVE-2026-87902: attackers now drop PHP that runs commands on unpatched WordPress. Patchstack: recon to RCE in <24h after 7.1.2. Patch core now. Source: BleepingComputer. Verify independently. #CyberSecurity #InfoSec #WordPress #CVE #ThreatIntel

    @ThreatAlis

    25 Sept 2026

    0 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. CVE-2026-87902こわい 昨日すぐアップデートした! 【WordPress】脆弱性CVE-2026-87902とは?影響するバージョンと対策を解説|みずかず式! https://t.co/8jOeLFdFYX

    @mizukazu_1

    25 Sept 2026

    125 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  6. WordPress CVE-2026-87902 under active attack. Unauth path traversal can lead to RCE; Patchstack reports PHP file writes and 10x scan traffic. Update to 7.1.2 now. Source: SecurityWeek/Patchstack. Verify independently. #CyberSecurity #InfoSec #WordPress #CVE #ThreatIntel

    @ThreatAlis

    25 Sept 2026

    0 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. WordPressの脆弱性CVE-2026-87902への対応を整理。対象バージョンの確認、更新、更新後の点検まで、管理者が押さえたい4手順をまとめました。🔎

    @new_ai_news

    25 Sept 2026

    34 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    2 Replies

    0 Quotes

  8. CVE-2026-87902: attackers now drop executable PHP on unpatched WordPress (4.7.0–7.1.1). Unauth path traversal can lead to RCE. Patch to 7.1.2. via BleepingComputer/Patchstack. Verify independently. #CyberSecurity #InfoSec #WordPress #CVE #ThreatIntel

    @ThreatAlis

    25 Sept 2026

    0 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. WordPress CVE-2026-87902: respuesta empresarial | Insylux Una guía empresarial para inventariar sitios, actualizar con recuperación, revisar evidencia y validar la corrección de CVE-2026-87902. #Wordpress #Insylux https://t.co/FzcyI1d4cK https://t.co/HohUerm77G

    @Insylux

    25 Sept 2026

    3 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  10. 【重要】WordPressの脆弱性(CVE-2026-87902)に関する注意喚起について https://t.co/5OBZMFjHiZ (エックスサーバー) #CA #クリアカ #WordPress 脆弱性 CVE-2026-87902 注意喚起 XServer #求職者支援訓練 #ハロトレ #IT #デザイン #AI 2026/

    @c_aca_webdesign

    25 Sept 2026

    56 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  11. 🔒 #CyberSecurity CVE-2026-87902: WordPress get_page_template() Exploited Within Hours — Detectio… "Within hours of public disclosure, threat actors began actively exploiting CVE-2026-87902,…" 🔗 https://t.co/JJJJITfhVQ #CyberSecurity #ThreatIntel #cve #zeroday

    @SecurityAr58409

    24 Sept 2026

    57 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  12. Patch Now | September 24, 2026 Bringing these vulnerabilities to your attention: - WordPress core (CVE-2026-87902, CVSS 9.2) - F5 BIG-IP APM (CVE-2026-94127, CVSS 9.8) - Arista VeloCloud Orchestrator (CVE-2026-93952, CVSS 10.0) https://t.co/fR71dypdSf | #CyberSafeUG #CERTUGCC h

    @CERT_UG

    24 Sept 2026

    111 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  13. CVE-2026-87902 Exploited to Write PHP Files on WordPress Sites Attackers are exploiting WordPress vulnerability CVE-2026-87902 to progress from file-inclusion probes to writing attacker-controlled PHP files through PEAR’s pearcmd.php, enabling code execution. The

    @LandscapeThreat

    24 Sept 2026

    19 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  14. 🔴 Attackers Exploit WordPress CVE-2026-87902 Within Hours of Disclosure Critical CVE / Exploit: Threat actors have begun to actively exploit a critical se... https://t.co/qaLmE90Ydf #CVE #CyberSecurity #Privacy #SecurityAlert

    @MyDooM15

    24 Sept 2026

    48 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  15. Attackers Exploit WordPress CVE-2026-87902 Within Hours of Disclosure: Threat actors have begun to actively exploit a critical security flaw in WordPress within hours of public disclosure. The vulnerability in question is CVE-2026-87902 (CVSS score:… https://t.co/NxI7mJQYXQ htt

    @shah_sheikh

    24 Sept 2026

    58 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  16. WordPress 7.1.2 patches CVE-2026-87902, a critical path traversal flaw that allows unauthenticated remote code execution. Update immediately. #WordPress #Wordfence #Security https://t.co/9o7GoFBF0E

    @WPtips

    23 Sept 2026

    219 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  17. WordPress 7.1.2 fixes critical unauthenticated path traversal vulnerability (CVE-2026-87902) https://t.co/vXU3QitHDi

    @TheCyberSecHub

    23 Sept 2026

    1077 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  18. 🚨 CRITICAL | WordPress Core — CVE-2026-87902 A PoC by @abraxas_null has been released for an unauthenticated Local File Inclusion (LFI) flaw. 🔴 CVE: CVE-2026-87902 ⚠️ CVSS 4.0: 9.2 Critical ⚠️ CVSS 3.1: 8.1 High 🎯 CWE-98 📌 Affected: ≤ 7.1.1

    @exploitgrid

    23 Sept 2026

    103 Impressions

    2 Retweets

    4 Likes

    1 Bookmark

    1 Reply

    0 Quotes

  19. CVE-2026-87902: how close is your #WordPress to remote code execution? https://t.co/Cs1QPR9jXJ #securityaffairs #hacking

    @securityaffairs

    23 Sept 2026

    157 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  20. Big alert for WordPress sites: CVE-2026-87902 lets attackers run PHP code without any login. Themes, server setup matter—update to version 7.1.2 now. #SecurityNews #WordPress #Vulnerability #CVE #WebSecurity #WordPress #Security #CVE2026 #RemoteCodeExecution #WebSecurity https

    @dailytechonx

    23 Sept 2026

    43 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  21. For defenders, cve-2026-87902: wordpress template rce risk should move fast. CVE-2026-87902 affects WordPress 4.7.0 through 7.1.1. Update to 7.1.2 or the matching backp… 🔗 Details → https://t.co/fXn1wafc9N

    @SocXAInvaders

    23 Sept 2026

    31 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  22. Probing already underway: CVE-2026-87902 is a critical WordPress Core LFI that can reach RCE. Patch to 7.1.2 or your branch backport now. Wordfence + Patchstack. Verify independently. #CyberSecurity #InfoSec #WordPress #CVE #Vulnerability

    @ThreatAlis

    23 Sept 2026

    0 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  23. WordPress sites are being probed for CVE-2026-87902 hours after the 7.1.2 patch. Unauthenticated path traversal in core (4.7–7.1.1) can become LFI/RCE on some themes. Update now. Wordfence + Patchstack. Verify independently. #CyberSecurity #InfoSec #WordPress #CVE #ThreatIntel

    @ThreatAlis

    23 Sept 2026

    0 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  24. 🛑 CVE-2026-87902: WordPress Template RCE Risk CVE-2026-87902 affects WordPress 4.7.0 through 7.1.1. Update to 7.1.2 or the matching backp… 🔗 Details → https://t.co/vIwHXZscwQ

    @lucasverdan

    23 Sept 2026

    61 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  25. WordPress 7.1.2 patches CVE-2026-87902: unauthenticated path traversal that can load local PHP files, and on some servers run code. Affects 4.7.0 through 7.1.1. Update now. https://t.co/qgPuvtlXPR

    @JustinMiddler

    23 Sept 2026

    35 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    1 Reply

    0 Quotes

  26. #SECURITY_ALERT CONFIRMED BY: WordPress Security Team PRODUCT: WordPress Core CVE: CVE-2026-87902 SEVERITY: Critical — CVSS v4.0 9.2 IMPACT: An unauthenticated attacker can manipulate page-template resolution to include a chosen readable local PHP file outside the active

    @Python_s_

    23 Sept 2026

    41 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes