What happened
WordPress has patched CVE-2026-87902, a critical path-traversal flaw in page-template resolution that can lead to conditional remote code execution. WordPress says an unauthenticated attacker can, under specific theme and server conditions, cause a site to include a readable local PHP file outside the active theme directories. The issue affects WordPress 4.7.0 through 7.1.1. WordPress 7.1.2 contains the fix, with security backports released for supported older branches.
Exploitation began almost immediately after disclosure. The Hacker News reported attempts involving local PHP files such as pearcmd.php, attacker-controlled PHP writes, and follow-on upload activity. On September 25, CISA added CVE-2026-87902 to its Known Exploited Vulnerabilities catalog.
Why it matters for website owners
The flaw does not produce RCE on every affected WordPress site. Exploitation depends on the active theme having a suitable top-level directory and a readable local PHP target that can be abused. Those prerequisites reduce the number of exploitable installations, but active scanning means owners should not rely on them as protection.
A successful compromise can allow code to run with the web-server account's privileges, which can lead to file changes, web shells, credential exposure, or further site takeover.
What to check on your site
- Update WordPress immediately. Current fixed branches include 7.1.2, 7.0.6, 6.9.9, and 6.8.10, with additional backports for older supported branches.
- Review recently created or modified PHP files, especially unexpected files in temporary directories or web-accessible locations.
- Check server and application logs for unusual template-resolution requests and unexplained administrator or file activity.
- Use Vulnify's WordPress Stack Checker to review publicly visible WordPress footprint and component intelligence. It does not prove whether CVE-2026-87902 is exploitable on a specific server.
Related reading
After patching, use the Post-Deployment Website Security Checklist to verify the live site, and review the Admin Panel Security Checklist if compromise indicators suggest account or privilege changes.
