VDB

CVE-2026-87902

CVE-2026-87902 PUBLISHED CVSS 8.1 HIGH

Reported by hackerone · Published September 22, 2026

An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the active theme directories. If relevant pre-conditions for both the server and the active theme are met, this can lead to RCE.

Risk Scores

CVSS 3.1
8.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersions
WordPressWordPress0
WordPressWordPress0

Timeline

  • Sep 22, 2026 VulnCheck KEV Exploitation
  • Sep 22, 2026 Coalition ESS Score
  • Sep 22, 2026 CVE Published
  • Sep 22, 2026 CVE Updated
  • Sep 23, 2026 VulnCheck XDB Entry

References

Open in Interactive Console →
$ Console Community · 100/wk Open console ›