« Back to list

CVE-2026-87902

Status: AnalyzedHigh (8.1)⚠ Active exploitation

An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the active theme directories. If relevant pre-conditions for both the server and the active theme are met, this can lead to RCE.

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

CISA KEV — actively exploited

Affected technologies (1)

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2026-87902",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-87902",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "active"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-09-25T00:00:00+00:00"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.1,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.2
      }
    ]
  },
  "affected": [
    {
      "source": "support@hackerone.com",
      "affectedData": [
        {
          "vendor": "WordPress",
          "product": "WordPress",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "7.1.2",
              "versionType": "semver"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2026-09-22T17:17:28.310",
  "references": [
    {
      "url": "https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-7hp8-65ch-5whp",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "support@hackerone.com"
    },
    {
      "url": "https://patchstack.com/articles/cve-2026-87902-attackers-started-probing-wordpress-sites-hours-after-the-patch/",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0"
    },
    {
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-87902",
      "tags": [
        "US Government Resource"
      ],
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "support@hackerone.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-98"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the active theme directories. If relevant pre-conditions for both the server and the active theme are met, this can lead to RCE."
    }
  ],
  "lastModified": "2026-09-28T12:20:54.040",
  "cisaActionDue": "2026-09-28",
  "cisaExploitAdd": "2026-09-25",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F1CFA516-E292-436E-9B45-BD6ACB344205",
              "versionEndExcluding": "4.7.37"
            },
            {
              "criteria": "cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8EEBFAB5-8903-4D4E-9847-A50A3F840878",
              "versionEndExcluding": "4.8.32",
              "versionStartIncluding": "4.8"
            },
            {
              "criteria": "cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5A7719CA-2099-45E9-8E48-64EF672C76C0",
              "versionEndExcluding": "4.9.33",
              "versionStartIncluding": "4.9"
            },
            {
              "criteria": "cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BFA3645E-7056-449B-9DEB-D9D53EB21488",
              "versionEndExcluding": "5.0.29",
              "versionStartIncluding": "5.0"
            },
            {
              "criteria": "cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3582671F-7248-420A-8DF7-F32742D0D2AF",
              "versionEndExcluding": "5.1.26",
              "versionStartIncluding": "5.1"
            },
            {
              "criteria": "cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FD9C147A-9FCB-46A7-8409-4AE652986FDC",
              "versionEndExcluding": "5.2.28",
              "versionStartIncluding": "5.2"
            },
            {
              "criteria": "cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "73C13CF0-B293-47C4-93AA-F46E0323A9C1",
              "versionEndExcluding": "5.3.25",
              "versionStartIncluding": "5.3"
            },
            {
              "criteria": "cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7FB5AE52-9590-4B1D-BDFF-A522EFDD55DC",
              "versionEndExcluding": "5.4.23",
              "versionStartIncluding": "5.4"
            },
            {
              "criteria": "cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "72A42175-5759-47B1-8E87-ADAF0CDB73C7",
              "versionEndExcluding": "5.5.22",
              "versionStartIncluding": "5.5"
            },
            {
              "criteria": "cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5D7C48F3-BBB2-4943-A6F2-E652997034FE",
              "versionEndExcluding": "5.6.21",
              "versionStartIncluding": "5.6"
            },
            {
              "criteria": "cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D23FACBB-B9EC-4490-B328-24833FEF6209",
              "versionEndExcluding": "5.7.19",
              "versionStartIncluding": "5.7"
            },
            {
              "criteria": "cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "47F4A57C-CA16-4E9A-B0C2-EBB5FCCB41B9",
              "versionEndExcluding": "5.8.17",
              "versionStartIncluding": "5.8"
            },
            {
              "criteria": "cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "83CC56B0-F56E-4862-B74E-B106092C73F0",
              "versionEndExcluding": "5.9.18",
              "versionStartIncluding": "5.9"
            },
            {
              "criteria": "cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E3EE7487-2943-4229-8B04-8787FE730FCB",
              "versionEndExcluding": "6.0.16",
              "versionStartIncluding": "6.0"
            },
            {
              "criteria": "cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E83A61A6-8FBC-4AF6-98E6-0152CA380AA0",
              "versionEndExcluding": "6.1.14",
              "versionStartIncluding": "6.1"
            },
            {
              "criteria": "cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D97C90F9-83C3-4057-A7E2-61787BC24E05",
              "versionEndExcluding": "6.2.13",
              "versionStartIncluding": "6.2"
            },
            {
              "criteria": "cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D7DA40D7-228A-4CFF-8CC8-32321BB1D3C5",
              "versionEndExcluding": "6.3.12",
              "versionStartIncluding": "6.3"
            },
            {
              "criteria": "cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DDE93788-7DAB-475C-B6AE-753780DE8160",
              "versionEndExcluding": "6.4.12",
              "versionStartIncluding": "6.4"
            },
            {
              "criteria": "cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "18808A77-C445-4D07-A364-A676F2D7FD63",
              "versionEndExcluding": "6.5.12",
              "versionStartIncluding": "6.5"
            },
            {
              "criteria": "cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "ADEAA29A-1862-476B-8F21-684D8799589E",
              "versionEndExcluding": "6.6.9",
              "versionStartIncluding": "6.6"
            },
            {
              "criteria": "cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D3BD738C-4601-43C1-A5BC-E5AFB0189CD9",
              "versionEndExcluding": "6.7.9",
              "versionStartIncluding": "6.7"
            },
            {
              "criteria": "cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4A6867FC-850F-437B-8532-63A5F747D64F",
              "versionEndExcluding": "6.8.10",
              "versionStartIncluding": "6.8"
            },
            {
              "criteria": "cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5C21A09B-5001-4F4E-A49D-4F29032AF612",
              "versionEndExcluding": "6.9.9",
              "versionStartIncluding": "6.9"
            },
            {
              "criteria": "cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6FC26EAE-8D7D-4BF9-AACE-75C6AB13279F",
              "versionEndExcluding": "7.0.6",
              "versionStartIncluding": "7.0"
            },
            {
              "criteria": "cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "525A2372-93E8-447E-BBB7-F795C08B3E2B",
              "versionEndExcluding": "7.1.2",
              "versionStartIncluding": "7.1"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "support@hackerone.com",
  "cisaRequiredAction": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
  "cisaVulnerabilityName": "WordPress Core Remote File Inclusion Vulnerability"
}