important · WordPress — RCE
WordPress page-template traversal has moved from a conditional primitive to observed PHP writes and command payloads.
Affects
WordPress Core, a self-hosted PHP content-management system.
A public, unauthenticated request can traverse outside the theme template directory. On systems with the required theme and PHP settings, attackers include pearcmd.php, write PHP into a temporary directory, and include it again for execution.
Detail and 4 sources
The new evidence is exploitation progressing from probes to file writes and shell commands. Fixed releases are available for supported WordPress branches.
Sources
ResearchCVE-2026-87902: Attackers Started Probing WordPress Sites Hours After the Patch - PatchstackResearchVersion 7.1.2 – Documentation – WordPress.orgCode / PoCGitHub - ressl/cve-2026-87902-poc: PoC for CVE-2026-87902 — unauthenticated path traversal in WordPress page-template resolution (local PHP inclusion, conditional RCE) with a pinned vulnerable labSecondaryUnauthenticated path traversal in page-template resolution leading to conditional RCE