DIRAS TAKE
Prioritize immediate action: this is a high-severity RCE with public exploit code and a CISA listing. Patch or apply mitigations without delay.
What is CVE-2026-87902?
A flaw in WordPress page-template resolution allows an unauthenticated actor to cause get_page_template() to pull in a local .php file that lies outside the active theme folders. When specific server settings and the active theme permit reading and inclusion of that file, an attacker can achieve remote code execution. The bug affects 7.x releases prior to 7.1.2 and only requires triggering the page-template logic plus those environmental conditions.
Vector CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of WordPress Core are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 7.x | before 7.1.2 | 7.1.2 |
Is CVE-2026-87902 being exploited?
CISA lists this vulnerability as exploited in the wild (added 2026-09-25). Public exploit code is available. Given published exploits and the CISA KEV entry, assume active exploitation risk as of 2026-09-29.
How to fix CVE-2026-87902
- Update WordPress 7.x installations to version 7.1.2.
- If patching is delayed, reduce internet exposure of affected sites and block or restrict access to endpoints that can trigger template resolution.
- Inspect web and PHP logs for attempts to manipulate template loading and for unexpected inclusions of local .php files.
- Follow vendor updates and apply any recommended configuration hardening and forensic steps per CISA guidance.
Frequently asked questions
Is CVE-2026-87902 being actively exploited?
Yes. CISA lists it as exploited in the wild (added 2026-09-25) and public exploit code exists.
Which versions are affected and what is the fixed version?
All 7.x branch releases before 7.1.2 are affected. The fix is included in 7.1.2.
What does an attacker need to exploit this?
No authentication is required to trigger the template logic, but the server and active theme must permit reading and including a local .php file for exploitation to result in code execution.
References
- nvd.nist.gov/vuln/detail/CVE-2026-87902
- cve.org/CVERecord?id=CVE-2026-87902
- cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-87902
- github.com/WordPress/wordpress-develop/security/advisories/GHSA-7hp8-65ch-5whp
- All WordPress CVEs on CVE Radar
- CVEs published in September 2026