important · Research
WordPress page-template traversal can lead to conditional unauthenticated PHP execution.
Affects
WordPress Core, the PHP content-management system used by public websites.
A valid page_id and double-encoded traversal can make template resolution include readable PHP outside the active theme.
Detail and 3 sources
Code execution additionally requires a qualifying theme layout, a usable local inclusion target, PEAR, and register_argc_argv; under those conditions pearcmd.php can write PHP that a second request executes as the web-server account.
WordPress has published a fix.
Sources
ResearchWordPress 7.1.2 Release – WordPress NewsResearchCVE-2026-87902: Attackers Started Probing WordPress Sites Hours After the Patch - PatchstackCode / PoCGitHub - ressl/cve-2026-87902-poc: PoC for CVE-2026-87902 — unauthenticated path traversal in WordPress page-template resolution (local PHP inclusion, conditional RCE) with a pinned vulnerable lab