Skip to main content Skip to local navigation

WordPress RCE (CVE-2026-87902)

 

A picture containing text  Description automatically generated

 

Information Security Advisory


A recently disclosed vulnerability (CVE-2026-87902) affects WordPress Core and may allow an unauthenticated remote attacker to achieve remote code execution (RCE) on vulnerable WordPress sites when specific theme and server conditions are present.

Severity level:
CVSS Score: 9.2/Critical.

Description:

CVE-2026-87902 is a critical path traversal vulnerability in WordPress Core's get_page_template() functionality. The flaw allows an unauthenticated attacker to manipulate page template resolution and cause WordPress to include a readable local PHP file located outside the active theme directory. Under specific conditions, including the presence of a theme directory beginning with page- and a suitable PHP file accessible to the web server, an attacker may leverage the vulnerability to execute arbitrary code and fully compromise the affected website.

Affected Versions:

  • WordPress core version prior to 7.1.2
  • Older WordPress branches 4.7.x through 7.1.x prior to their respective security updates.

 

Impact:
Successful exploitation may allow attackers to gain unauthorized access to the WordPress environment.

Resolution:
Upgrade WordPress immediately to a patched version appropriate to the branch:-

  • WordPress 7.1.2 or later.
  • WordPress security releases for 7.0.x, 6.9.x, 6.8.x and older supported branches.

 

Reference:

https://www.cyber.gc.ca/en/alerts-advisories/wordpress-security-advisory-av26-952

https://www.helpnetsecurity.com/2026/09/23/cve-2026-87902-wordpress-7-1-2-security-release/

https://thehackernews.com/2026/09/attackers-exploit-wordpress-cve-2026.html

https://securityaffairs.com/199564/hacking/cve-2026-87902-how-close-is-your-wordpress-to-remote-code-execution.html

https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-7hp8-65ch-5whp

 


UIT Information Security




Contact

IT Client Services at askIT@yorku.ca or 416 736 5800

 

PRIVACY POLICY | VISIT WWW.YORKU.CA
This email was sent by: York University, 4700 Keele Street, Toronto, Ontario M3J 1P3

This email is viewed best in Microsoft Outlook for web