important · Edge — WordPress
WordPress page-template traversal can write PHP and execute code without authentication on affected configurations.
Affects
WordPress Core, the PHP content-management system used by self-hosted websites.
The complete chain depends on an affected theme layout and a readable local execution target such as pearcmd.php, which can turn local inclusion into an attacker-controlled PHP write.
Detail and 4 sources
Sources
ResearchWordPress 7.1.2 ReleaseResearchCVE-2026-87902: Attackers Started Probing WordPress Sites Hours After the Patch - PatchstackSecondaryWordPress CVE-2026-87902 is now associated with active exploitationSecondaryPublic exploit and detection material released for exploited F5 BIG-IP APM CVE-2026-94127