Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Workaround
WordPress 7.1.2 has been released containing a fix for the vulnerability, and as a courtesy to users on older branches the fix has been backported to all branches back to 4.7.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 22 Sep 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wordpress
Wordpress wordpress |
|
| Vendors & Products |
Wordpress
Wordpress wordpress |
Tue, 22 Sep 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Tue, 22 Sep 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the active theme directories. If relevant pre-conditions for both the server and the active theme are met, this can lead to RCE. | |
| Weaknesses | CWE-98 | |
| References |
|
Status: PUBLISHED
Assigner: hackerone
Published:
Updated: 2026-09-22T16:57:26.510Z
Reserved: 2026-09-09T15:00:00.574Z
Link: CVE-2026-87902
Updated: 2026-09-22T16:57:19.735Z
Status : Received
Published: 2026-09-22T17:17:28.310
Modified: 2026-09-22T17:17:28.310
Link: CVE-2026-87902
No data.
OpenCVE Enrichment
Updated: 2026-09-22T17:30:18Z
-
CWE-98
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')