AllCyberNews

CVE-2026-87902

WordPress 7.1.2 fixes critical unauthenticated path traversal vulnerability (CVE-2026-87902)

CVSS 8.1 high · WordPress WordPress · published 2026-09-22

An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the active theme directories. If relevant pre-conditions for both the server and the active theme are met, this can lead to RCE.

Coverage 1 source

  1. 2026-09-23 Help Net Security critical WordPress 7.1.2 fixes critical unauthenticated path traversal vulnerability (CVE-2026-87902)

    WordPress 7.1.2 patches a critical unauthenticated path traversal vulnerability.

Also covered