A recently disclosed vulnerability (CVE-2026-87902) affects WordPress Core and may allow an unauthenticated remote attacker to achieve remote code execution (RCE) on vulnerable WordPress sites when specific theme and server conditions are present. Severity level: CVSS Score: 9.2/Critical. Description: CVE-2026-87902 is a critical path traversal vulnerability in WordPress Core's get_page_template() functionality. The flaw allows an unauthenticated attacker to manipulate page template resolution and cause WordPress to include a readable local PHP file located outside the active theme directory. Under specific conditions, including the presence of a theme directory beginning with page- and a suitable PHP file accessible to the web server, an attacker may leverage the vulnerability to execute arbitrary code and fully compromise the affected website. Affected Versions:
WordPress core version prior to 7.1.2
Older WordPress branches 4.7.x through 7.1.x prior to their respective security updates.
Impact: Successful exploitation may allow attackers to gain unauthorized access to the WordPress environment. Resolution: Upgrade WordPress immediately to a patched version appropriate to the branch:-
WordPress 7.1.2 or later.
WordPress security releases for 7.0.x, 6.9.x, 6.8.x and older supported branches.