CVE Details

CVE-2026-87902 WordPress Core Remote File Inclusion Vulnerability
Published: 2026-09-25 CVSS: 8.1 HIGH Product: WordPress Core Due Date: 2026-09-28

WordPress Core contains a remote file inclusion vulnerability which could allow an unauthenticated attacker to make page-template resolution include a chosen readable local `.php` file outside the active theme directories, leading to remote code execution.

GitHub PoC

Warning: GitHub PoC repositories are unverified. Some may be fake or contain malware. Use caution and review code before running anything.
  • 0xMarcio/pocindex • ⭐ 1414 • 2024-05-24 • Conf: 93.0%
  • Search 82,000+ public CVE proof-of-concept exploits from GitHub, Nuclei, ExploitDB, Metasploit and Vulhub.
  • ressl/cve-2026-87902-poc • ⭐ 30 • 2026-09-22 • Conf: 95.0%
  • PoC for CVE-2026-87902 — unauthenticated path traversal in WordPress page-template resolution (local PHP inclusion, conditional RCE) with a pinned vulnerable lab
  • abraxas/CVE-2026-87902 • ⭐ 29 • 2026-09-22 • Conf: 95.0%
  • CVE-2026-87902 - WordPress - WordPress Core - Critical 9.2 - Unauthenticated Local File Inclusion (conditional RCE)

FIRST EPSS

EPSS estimates the probability of exploitation in the next 30 days. Higher values indicate higher likelihood of real-world exploitation.

Timeline

CVE Stalker KEV MITRE GitHub FIRST (EPSS)

MITRE

CVSS

  • Score: 8.1
  • Severity: HIGH
  • Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

SSVC

  • Exploitation: active
  • Automatable: no
  • Technical Impact: total

References

Show Raw Data
Key Remaining Key Value
dataType CVE_RECORD
dataVersion 5.2
cveMetadata > cveId CVE-2026-87902
cveMetadata > assignerOrgId 36234546-b8fa-4601-9d6f-f4e334aa8ea1
cveMetadata > state PUBLISHED
cveMetadata > assignerShortName hackerone
cveMetadata > dateReserved 2026-09-09T15:00:00.574Z
cveMetadata > datePublished 2026-09-22T16:44:15.048Z
cveMetadata > dateUpdated 2026-09-25T19:43:19.946Z
containers > cna > descriptions > 0 > lang en
containers > cna > descriptions > 0 > value An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the active theme directories. If relevant pre-conditions for both the server and the active theme are met, this can lead to RCE.
containers > cna > affected > 0 > defaultStatus unaffected
containers > cna > affected > 0 > vendor WordPress
containers > cna > affected > 0 > product WordPress
containers > cna > affected > 0 > versions > 0 > version 0
containers > cna > affected > 0 > versions > 0 > status affected
containers > cna > affected > 0 > versions > 0 > lessThan 7.1.2
containers > cna > affected > 0 > versions > 0 > versionType semver
containers > cna > references > 0 > url https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-7hp8-65ch-5whp
containers > cna > problemTypes > 0 > descriptions > 0 > type CWE
containers > cna > problemTypes > 0 > descriptions > 0 > lang en
containers > cna > problemTypes > 0 > descriptions > 0 > cweId CWE-98
containers > cna > problemTypes > 0 > descriptions > 0 > description CWE-98 Remote File Inclusion
containers > cna > credits > 0 > lang en
containers > cna > credits > 0 > value Robert (ressl)
containers > cna > credits > 0 > type finder
containers > cna > workarounds > 0 > lang en
containers > cna > workarounds > 0 > value WordPress 7.1.2 has been released containing a fix for the vulnerability, and as a courtesy to users on older branches the fix has been backported to all branches back to 4.7.
containers > cna > providerMetadata > orgId 36234546-b8fa-4601-9d6f-f4e334aa8ea1
containers > cna > providerMetadata > shortName hackerone
containers > cna > providerMetadata > dateUpdated 2026-09-22T16:44:15.048Z
containers > adp > 0 > metrics > 0 > cvssV3_1 > scope UNCHANGED
containers > adp > 0 > metrics > 0 > cvssV3_1 > version 3.1
containers > adp > 0 > metrics > 0 > cvssV3_1 > baseScore 8.1
containers > adp > 0 > metrics > 0 > cvssV3_1 > attackVector NETWORK
containers > adp > 0 > metrics > 0 > cvssV3_1 > baseSeverity HIGH
containers > adp > 0 > metrics > 0 > cvssV3_1 > vectorString CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
containers > adp > 0 > metrics > 0 > cvssV3_1 > integrityImpact HIGH
containers > adp > 0 > metrics > 0 > cvssV3_1 > userInteraction NONE
containers > adp > 0 > metrics > 0 > cvssV3_1 > attackComplexity HIGH
containers > adp > 0 > metrics > 0 > cvssV3_1 > availabilityImpact HIGH
containers > adp > 0 > metrics > 0 > cvssV3_1 > privilegesRequired NONE
containers > adp > 0 > metrics > 0 > cvssV3_1 > confidentialityImpact HIGH
containers > adp > 0 > metrics > 1 > other > type ssvc
containers > adp > 0 > metrics > 1 > other > content > id CVE-2026-87902
containers > adp > 0 > metrics > 1 > other > content > role CISA Coordinator
containers > adp > 0 > metrics > 1 > other > content > options > 0 > Exploitation active
containers > adp > 0 > metrics > 1 > other > content > options > 1 > Automatable no
containers > adp > 0 > metrics > 1 > other > content > options > 2 > Technical Impact total
containers > adp > 0 > metrics > 1 > other > content > version 2.0.3
containers > adp > 0 > metrics > 1 > other > content > timestamp 2026-09-25T19:40:04.026420Z
containers > adp > 0 > references > 0 > url https://patchstack.com/articles/cve-2026-87902-attackers-started-probing-wordpress-sites-hours-after-the-patch/
containers > adp > 0 > references > 0 > tags > 0 third-party-advisory
containers > adp > 0 > references > 1 > url https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-87902
containers > adp > 0 > references > 1 > tags > 0 government-resource
containers > adp > 0 > title CISA ADP Vulnrichment
containers > adp > 0 > providerMetadata > orgId 134c704f-9b21-4f2e-91b3-4a467353bcc0
containers > adp > 0 > providerMetadata > shortName CISA-ADP
containers > adp > 0 > providerMetadata > dateUpdated 2026-09-25T19:43:19.946Z