Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4196 articles · 221935 vulns · 36/41 feeds (7d)
← Back to list
8.1
CVE-2026-87902KEVEXPLOITEDPATCHED
WordPress · WordPress

CVE-2026-87902: An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.ph

Description

An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the active theme directories. If relevant pre-conditions for both the server and the active theme are met, this can lead to RCE.

Affected Products

VendorProductVersions
WordPressWordPress0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
fedorafedora linuxcert_advisory90%
open sourcewordpresscert_advisory90%

References

  • https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-7hp8-65ch-5whp
  • https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-87902.yaml(exploit, nuclei)

Related News (10 articles)

Tier E
Reddit r/cybersecurity3h ago
Attackers Exploit WordPress CVE-2026-87902 Within Hours of Disclosure
→ No new info (linked only)
Tier B
BSI Advisories3h ago
[NEU] [kritisch] WordPress: Schwachstelle ermöglicht Codeausführung
→ No new info (linked only)
Tier D
The Hacker News8h ago
Attackers Exploit WordPress CVE-2026-87902 Within Hours of Disclosure
→ No new info (linked only)
Tier D
BleepingComputer20h ago
Hackers start exploiting critical WordPress flaw for code execution
→ No new info (linked only)
Tier B
CCCS Canada23h ago
WordPress security advisory (AV26-952)
→ No new info (linked only)
Tier D
Help Net Security1d ago
WordPress 7.1.2 fixes critical unauthenticated path traversal vulnerability (CVE-2026-87902)
→ No new info (linked only)
Tier B
CERT-FR1d ago
Vulnérabilité dans WordPress (23 septembre 2026)
→ No new info (linked only)
Tier D
Heise Security1d ago
Gleich noch ein Sicherheitsupdate für WordPress
→ No new info (linked only)
Tier D
The Hacker News1d ago
WordPress Issues Patch for Critical Flaw That Can Enable Code Execution on Some Servers
→ No new info (linked only)
Tier C
VulDB1d ago
CVE-2026-87902 | WordPress up to 7.1.1 Page Template Resolution get_page_template path traversal
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.18.1 HIGH
VectorCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA KEV✅ Yes
Actively exploited✅ Yes
Patch available
7.1.2
CWECWE-98
PublishedSep 22, 2026
Last enriched1d ago
Trending Score137🔥
Source articles10
Independent9
Info Completeness9/14
Missing: epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-63030EXPKEV
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
Trending: 4
MEDIUMCVE-2026-60137EXPKEV
WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_Query
Trending: 3
HIGHCVE-2026-65640
CVE-2026-65640: WordPress is vulnerable to a remote code execution vulnerability via malicious Postscript file upload by an Author level
Trending: 1
NONECVE-2026-64638
CVE-2026-64638: WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a specially crafted malici
Trending: 1
CRITICALCVE-2026-6382EXP
Multiple elFinder Plugins - Authenticated OS Command Injection

Pin to Dashboard

Verification

State: verified
Confidence: 0%

Vulnerability Timeline

CVE Published
Sep 22, 2026
Added to CISA KEV
Sep 22, 2026
Discovered by ZDM
Sep 22, 2026
Actively Exploited
Sep 22, 2026
Exploit Available
Sep 22, 2026
Patch Available
Sep 22, 2026