Skip to content

CVE-2026-87902

WordPress unauthenticated page-template path traversal can lead to RCE (CVE-2026-87902)

High 8.1 KEV Vendor: WordPress Published · Updated

Unauthenticated page-template path traversal in WordPress before 7.1.2 can lead to remote code execution under specific conditions. CISA KEV records active exploitation. Apply the vendor's branch-specific update, including 7.1.2, immediately.

What happened

CVE-2026-87902 is an unauthenticated path traversal in WordPress page-template resolution. An attacker can cause get_page_template() to include a chosen readable local .php file outside the active theme directories. The vulnerability is reachable over the network without authentication and without user interaction, but the attack has high complexity; remote code execution is achieved only when particular server and active-theme preconditions are met. The CVSS v3.1 score is 8.1, severity high.

CISA added this CVE to its Known Exploited Vulnerabilities catalog on 25 September 2026, with a due date of 28 September 2026. CISA's SSVC assessment records exploitation status as active. WordPress's advisory is GHSA-7hp8-65ch-5whp and rates the issue critical.

Who is affected

WordPress before 7.1.2 is affected. WordPress is a content management system. Internet-exposed installations are the most relevant, because the weakness is reachable over the network without credentials. The vendor has published multiple fixed releases, including 4.7.37, 6.8.10, 7.0.6 and 7.1.2; the full list is in the vendor advisory. The vendor rates the issue critical, but the advisory does not detail the server and theme preconditions required for remote code execution.

What to do now

  1. Update to a fixed release. The vendor advisory GHSA-7hp8-65ch-5whp lists these fixed versions: 4.7.37, 4.8.32, 4.9.33, 5.0.29, 5.1.26, 5.2.28, 5.3.25, 5.4.23, 5.5.22, 5.6.21, 5.7.19, 5.8.17, 5.9.18, 6.0.16, 6.1.14, 6.2.13, 6.3.12, 6.4.12, 6.5.12, 6.6.9, 6.7.9, 6.8.10, 6.9.9, 7.0.6, 7.1.2. Apply the release that matches your installed version or branch.
  2. Follow CISA's KEV required action. CISA's due date is 28 September 2026. Apply mitigations in accordance with vendor instructions and CISA's BOD 26-04 guidance. For cloud services, follow the applicable BOD 26-04 guidance or discontinue use if mitigations are unavailable.
  3. No workaround has been published. If you cannot patch immediately, restrict unnecessary internet exposure of WordPress installations and monitor for unusual page-template requests.

How to detect it

The Patchstack article linked in the references reports that attackers began probing WordPress sites hours after the patch. Watch for requests that attempt to influence page-template resolution or include local .php files outside the active theme. If your installation is internet-exposed, review web server logs for unusual template path parameters. The vendor has not published specific indicators of compromise.

Beyond the patch

Because CISA records active exploitation and the vector is reachable over the network without credentials, detection and containment deserve the same priority as patching. Managed Detection & Response (MDR) can watch for post-exploitation activity on WordPress hosts, while Virtual CISO Services (vCISO) helps you find and reduce internet-exposed WordPress assets before the next CVE.

Affected and fixed versions

ProductAffectedFixed in
WordPress– < 7.1.27.1.2
.8.32, 4.9.33, 5.0.29, 5.1.26, 5.2.28, 5.3.25, 5.4.23, 5.5.22, 5.6.21, 5.7.19, 5.8.17, 5.9.18, 6.0.16, 6.1.14, 6.2.13, 6.3.12, 6.4.12, 6.5.12, 6.6.9, 6.7.9, 6.8.10, 6.9.9, 7.0.6, 7.1.2

References

Sources: the CVE record (MITRE), NVD, CISA KEV and SSVC, ENISA EUVD, FIRST EPSS and the vendor's own advisory. Scores and dates are shown as those sources publish them.

Written with AI assistance from the sources above and checked automatically against them before publication.