{"id":"CVE-2026-87902","published":"2026-09-22T17:17:28.310","lastModified":"2026-09-28T12:20:54.040","description":"An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the active theme directories. If relevant pre-conditions for both the server and the active theme are met, this can lead to RCE.","cvssScore":8.1,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","cwes":["CWE-98"],"vendors":["wordpress"],"products":["wordpress"],"references":[{"url":"https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-7hp8-65ch-5whp","tags":["Vendor Advisory"]},{"url":"https://patchstack.com/articles/cve-2026-87902-attackers-started-probing-wordpress-sites-hours-after-the-patch/","tags":["Third Party Advisory"]},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-87902","tags":["US Government Resource"]}],"exploitRefs":[{"url":"https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-7hp8-65ch-5whp","tags":["Vendor Advisory"]}],"hasPoc":true,"ai":null}