- Description
- An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the active theme directories. If relevant pre-conditions for both the server and the active theme are met, this can lead to RCE.
- Source
- support@hackerone.com
- NVD status
- Undergoing Analysis
CVSS 3.1
- Type
- Secondary
- Base score
- 8.1
- Impact score
- 5.9
- Exploitability score
- 2.2
- Vector string
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- HIGH
- support@hackerone.com
- CWE-98
- Hype score
- Not currently trending
6 new OPEN, 7 new PRO (6 + 1) CVE-2026-17633 (IBM Langflow RCE), CVE-2026-87902 (Wordpress Core Template Path Traversal), CVE-2026-42779 (Apache MINA Allowlist Bypass RCE), TA569, and more. https://t.co/rV4vsQj0Kf
@ET_Labs
25 Sept 2026
125 Impressions
2 Retweets
0 Likes
1 Bookmark
0 Replies
0 Quotes
WordPress CVE-2026-87902 is being exploited in the wild. Attackers are exploiting a critical WordPress flaw within hours of disclosure: - CVE-2026-87902, CVSS 9.2 - Unauthenticated RCE via path traversal - Active exploitation confirmed by The Hacker News Patch immediately if
@so_sthbryan
25 Sept 2026
43 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
Attackers Exploit WordPress CVE-2026-87902 Within Hours of Disclosure(WordPressのCVE-2026-87902、公開から数時間で攻撃者が悪用) #TheHackerNews (Sep 24) https://t.co/eBUJePv4NO
@foxbook
25 Sept 2026
337 Impressions
0 Retweets
2 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2026-87902: attackers now drop PHP that runs commands on unpatched WordPress. Patchstack: recon to RCE in <24h after 7.1.2. Patch core now. Source: BleepingComputer. Verify independently. #CyberSecurity #InfoSec #WordPress #CVE #ThreatIntel
@ThreatAlis
25 Sept 2026
0 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2026-87902こわい 昨日すぐアップデートした! 【WordPress】脆弱性CVE-2026-87902とは?影響するバージョンと対策を解説|みずかず式! https://t.co/8jOeLFdFYX
@mizukazu_1
25 Sept 2026
125 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
WordPress CVE-2026-87902 under active attack. Unauth path traversal can lead to RCE; Patchstack reports PHP file writes and 10x scan traffic. Update to 7.1.2 now. Source: SecurityWeek/Patchstack. Verify independently. #CyberSecurity #InfoSec #WordPress #CVE #ThreatIntel
@ThreatAlis
25 Sept 2026
0 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
WordPressの脆弱性CVE-2026-87902への対応を整理。対象バージョンの確認、更新、更新後の点検まで、管理者が押さえたい4手順をまとめました。🔎
@new_ai_news
25 Sept 2026
34 Impressions
0 Retweets
0 Likes
0 Bookmarks
2 Replies
0 Quotes
CVE-2026-87902: attackers now drop executable PHP on unpatched WordPress (4.7.0–7.1.1). Unauth path traversal can lead to RCE. Patch to 7.1.2. via BleepingComputer/Patchstack. Verify independently. #CyberSecurity #InfoSec #WordPress #CVE #ThreatIntel
@ThreatAlis
25 Sept 2026
0 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
WordPress CVE-2026-87902: respuesta empresarial | Insylux Una guía empresarial para inventariar sitios, actualizar con recuperación, revisar evidencia y validar la corrección de CVE-2026-87902. #Wordpress #Insylux https://t.co/FzcyI1d4cK https://t.co/HohUerm77G
@Insylux
25 Sept 2026
3 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
【重要】WordPressの脆弱性(CVE-2026-87902)に関する注意喚起について https://t.co/5OBZMFjHiZ (エックスサーバー) #CA #クリアカ #WordPress 脆弱性 CVE-2026-87902 注意喚起 XServer #求職者支援訓練 #ハロトレ #IT #デザイン #AI 2026/
@c_aca_webdesign
25 Sept 2026
56 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🔒 #CyberSecurity CVE-2026-87902: WordPress get_page_template() Exploited Within Hours — Detectio… "Within hours of public disclosure, threat actors began actively exploiting CVE-2026-87902,…" 🔗 https://t.co/JJJJITfhVQ #CyberSecurity #ThreatIntel #cve #zeroday
@SecurityAr58409
24 Sept 2026
57 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
Patch Now | September 24, 2026 Bringing these vulnerabilities to your attention: - WordPress core (CVE-2026-87902, CVSS 9.2) - F5 BIG-IP APM (CVE-2026-94127, CVSS 9.8) - Arista VeloCloud Orchestrator (CVE-2026-93952, CVSS 10.0) https://t.co/fR71dypdSf | #CyberSafeUG #CERTUGCC h
@CERT_UG
24 Sept 2026
111 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
CVE-2026-87902 Exploited to Write PHP Files on WordPress Sites Attackers are exploiting WordPress vulnerability CVE-2026-87902 to progress from file-inclusion probes to writing attacker-controlled PHP files through PEAR’s pearcmd.php, enabling code execution. The
@LandscapeThreat
24 Sept 2026
19 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🔴 Attackers Exploit WordPress CVE-2026-87902 Within Hours of Disclosure Critical CVE / Exploit: Threat actors have begun to actively exploit a critical se... https://t.co/qaLmE90Ydf #CVE #CyberSecurity #Privacy #SecurityAlert
@MyDooM15
24 Sept 2026
48 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Attackers Exploit WordPress CVE-2026-87902 Within Hours of Disclosure: Threat actors have begun to actively exploit a critical security flaw in WordPress within hours of public disclosure. The vulnerability in question is CVE-2026-87902 (CVSS score:… https://t.co/NxI7mJQYXQ htt
@shah_sheikh
24 Sept 2026
58 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
WordPress 7.1.2 patches CVE-2026-87902, a critical path traversal flaw that allows unauthenticated remote code execution. Update immediately. #WordPress #Wordfence #Security https://t.co/9o7GoFBF0E
@WPtips
23 Sept 2026
219 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
WordPress 7.1.2 fixes critical unauthenticated path traversal vulnerability (CVE-2026-87902) https://t.co/vXU3QitHDi
@TheCyberSecHub
23 Sept 2026
1077 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 CRITICAL | WordPress Core — CVE-2026-87902 A PoC by @abraxas_null has been released for an unauthenticated Local File Inclusion (LFI) flaw. 🔴 CVE: CVE-2026-87902 ⚠️ CVSS 4.0: 9.2 Critical ⚠️ CVSS 3.1: 8.1 High 🎯 CWE-98 📌 Affected: ≤ 7.1.1
@exploitgrid
23 Sept 2026
103 Impressions
2 Retweets
4 Likes
1 Bookmark
1 Reply
0 Quotes
CVE-2026-87902: how close is your #WordPress to remote code execution? https://t.co/Cs1QPR9jXJ #securityaffairs #hacking
@securityaffairs
23 Sept 2026
157 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Big alert for WordPress sites: CVE-2026-87902 lets attackers run PHP code without any login. Themes, server setup matter—update to version 7.1.2 now. #SecurityNews #WordPress #Vulnerability #CVE #WebSecurity #WordPress #Security #CVE2026 #RemoteCodeExecution #WebSecurity https
@dailytechonx
23 Sept 2026
43 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
For defenders, cve-2026-87902: wordpress template rce risk should move fast. CVE-2026-87902 affects WordPress 4.7.0 through 7.1.1. Update to 7.1.2 or the matching backp… 🔗 Details → https://t.co/fXn1wafc9N
@SocXAInvaders
23 Sept 2026
31 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Probing already underway: CVE-2026-87902 is a critical WordPress Core LFI that can reach RCE. Patch to 7.1.2 or your branch backport now. Wordfence + Patchstack. Verify independently. #CyberSecurity #InfoSec #WordPress #CVE #Vulnerability
@ThreatAlis
23 Sept 2026
0 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
WordPress sites are being probed for CVE-2026-87902 hours after the 7.1.2 patch. Unauthenticated path traversal in core (4.7–7.1.1) can become LFI/RCE on some themes. Update now. Wordfence + Patchstack. Verify independently. #CyberSecurity #InfoSec #WordPress #CVE #ThreatIntel
@ThreatAlis
23 Sept 2026
0 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🛑 CVE-2026-87902: WordPress Template RCE Risk CVE-2026-87902 affects WordPress 4.7.0 through 7.1.1. Update to 7.1.2 or the matching backp… 🔗 Details → https://t.co/vIwHXZscwQ
@lucasverdan
23 Sept 2026
61 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
WordPress 7.1.2 patches CVE-2026-87902: unauthenticated path traversal that can load local PHP files, and on some servers run code. Affects 4.7.0 through 7.1.1. Update now. https://t.co/qgPuvtlXPR
@JustinMiddler
23 Sept 2026
35 Impressions
0 Retweets
1 Like
0 Bookmarks
1 Reply
0 Quotes
#SECURITY_ALERT CONFIRMED BY: WordPress Security Team PRODUCT: WordPress Core CVE: CVE-2026-87902 SEVERITY: Critical — CVSS v4.0 9.2 IMPACT: An unauthenticated attacker can manipulate page-template resolution to include a chosen readable local PHP file outside the active
@Python_s_
23 Sept 2026
41 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes