CVE-2026-87902 is a vulnerability in WordPress
Published on September 22, 2026
An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the active theme directories. If relevant pre-conditions for both the server and the active theme are met, this can lead to RCE.
Vulnerability Analysis
CVE-2026-87902 is exploitable with network access, and does not require authorization privileges or user interaction. This vulnerability is consided to have a high level of attack complexity. The potential impact of an exploit of this vulnerability is considered to be very high.
Weakness Type
What is a Remote file include Vulnerability?
The PHP application receives input from an upstream component, but it does not restrict or incorrectly restricts the input before its usage in "require," "include," or similar functions. In certain versions and configurations of PHP, this can allow an attacker to specify a URL to a remote location from which the software will obtain the code to execute. In other cases in association with path traversal, the attacker can specify a local file that may contain executable statements that can be parsed by PHP.
CVE-2026-87902 has been classified to as a Remote file include vulnerability or weakness.
Products Associated with CVE-2026-87902
Want to know whenever a new CVE is published for WordPress? stack.watch will email you.
Affected Versions
WordPress:- Before 7.1.2 is affected.