8.1

CVE-2026-87902

Warnung
Medienbericht

Unauthenticated path traversal in page-template resolution leading to conditional RCE

WordPress Core <= 7.1.1 - Unauthenticated Local File Inclusion via locate_template() Path Traversal

An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the active theme directories. If relevant pre-conditions for both the server and the active theme are met, this can lead to RCE.
Mögliche Gegenmaßnahme
WordPress Core: Install latest version
WordPress: Update to one of the following versions, or a newer patched version: 4.7.37, 4.8.32, 4.9.33, 5.0.29, 5.1.26, 5.2.28, 5.3.25, 5.4.23, 5.5.22, 5.6.21, 5.7.19, 5.8.17, 5.9.18, 6.0.16, 6.1.14, 6.2.13, 6.3.12, 6.4.12, 6.5.12, 6.6.9, 6.7.9, 6.8.10, 6.9.9, 7.0.6, 7.1.2
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Wordpress ≫ Wordpress Version < 4.7.37
Wordpress ≫ Wordpress Version >= 4.8 < 4.8.32
Wordpress ≫ Wordpress Version >= 4.9 < 4.9.33
Wordpress ≫ Wordpress Version >= 5.0 < 5.0.29
Wordpress ≫ Wordpress Version >= 5.1 < 5.1.26
Wordpress ≫ Wordpress Version >= 5.2 < 5.2.28
Wordpress ≫ Wordpress Version >= 5.3 < 5.3.25
Wordpress ≫ Wordpress Version >= 5.4 < 5.4.23
Wordpress ≫ Wordpress Version >= 5.5 < 5.5.22
Wordpress ≫ Wordpress Version >= 5.6 < 5.6.21
Wordpress ≫ Wordpress Version >= 5.7 < 5.7.19
Wordpress ≫ Wordpress Version >= 5.8 < 5.8.17
Wordpress ≫ Wordpress Version >= 5.9 < 5.9.18
Wordpress ≫ Wordpress Version >= 6.0 < 6.0.16
Wordpress ≫ Wordpress Version >= 6.1 < 6.1.14
Wordpress ≫ Wordpress Version >= 6.2 < 6.2.13
Wordpress ≫ Wordpress Version >= 6.3 < 6.3.12
Wordpress ≫ Wordpress Version >= 6.4 < 6.4.12
Wordpress ≫ Wordpress Version >= 6.5 < 6.5.12
Wordpress ≫ Wordpress Version >= 6.6 < 6.6.9
Wordpress ≫ Wordpress Version >= 6.7 < 6.7.9
Wordpress ≫ Wordpress Version >= 6.8 < 6.8.10
Wordpress ≫ Wordpress Version >= 6.9 < 6.9.9
Wordpress ≫ Wordpress Version >= 7.0 < 7.0.6
Wordpress ≫ Wordpress Version >= 7.1 < 7.1.2
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Weitere Schwachstelleninformationen
System
≫
Produkt WordPress Core
Version >= 7.1.0, < 7.1.2
Version >= 7.0.0, < 7.0.6
Version >= 6.9.0, < 6.9.9
Version >= 6.8.0, < 6.8.10
Version >= 6.7.0, < 6.7.9
Version >= 6.6.0, < 6.6.9
Version >= 6.5.0, < 6.5.12
Version >= 6.4.0, < 6.4.12
Version >= 6.3.0, < 6.3.12
Version >= 6.2.0, < 6.2.13
Version >= 6.1.0, < 6.1.14
Version >= 6.0.0, < 6.0.16
Version >= 5.9.0, < 5.9.18
Version >= 5.8.0, < 5.8.17
Version >= 5.7.0, < 5.7.19
Version >= 5.6.0, < 5.6.21
Version >= 5.5.0, < 5.5.22
Version >= 5.4.0, < 5.4.23
Version >= 5.3.0, < 5.3.25
Version >= 5.2.0, < 5.2.28
Version >= 5.1.0, < 5.1.26
Version >= 5.0.0, < 5.0.29
Version >= 4.9.0, < 4.9.33
Version >= 4.8.0, < 4.8.32
Version >= 4.7.0, < 4.7.37
SystemWordPress Core
≫
Produkt WordPress
Version 4.7-4.7.36
Version 4.8-4.8.31
Version 4.9-4.9.32
Version 5.0-5.0.28
Version 5.1-5.1.25
Version 5.2-5.2.27
Version 5.3-5.3.24
Version 5.4-5.4.22
Version 5.5-5.5.21
Version 5.6-5.6.20
Version 5.7-5.7.18
Version 5.8-5.8.16
Version 5.9-5.9.17
Version 6.0-6.0.15
Version 6.1-6.1.13
Version 6.2-6.2.12
Version 6.3-6.3.11
Version 6.4-6.4.11
Version 6.5-6.5.11
Version 6.6-6.6.8
Version 6.7-6.7.8
Version 6.8-6.8.9
Version 6.9-6.9.8
Version 7.0-7.0.5
Version 7.1-7.1.1

25.09.2026: CISA Known Exploited Vulnerabilities (KEV) Catalog

WordPress Core Remote File Inclusion Vulnerability

Schwachstelle

WordPress Core contains a remote file inclusion vulnerability which could allow an unauthenticated attacker to make page-template resolution include a chosen readable local `.php` file outside the active theme directories, leading to remote code execution.

Beschreibung

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Erforderliche Maßnahmen
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.88% 0.863
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
CISA-ADP 8.1 2.2 5.9
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-98 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')

The PHP application receives input from an upstream component, but it does not restrict or incorrectly restricts the input before its usage in "require," "include," or similar functions.

Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
28.09.2026 16:28
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
25.09.2026 13:34
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
24.09.2026 10:47
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
23.09.2026 20:46
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
22.09.2026 21:30
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
22.09.2026 21:00
https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-7hp8-65ch-5whp
Vendor Advisory
https://patchstack.com/articles/cve-2026-87902-attackers-started-probing-wordpress-sites-hours-after-the-patch/
Third Party Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-87902
US Government Resource
https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-7hp8-65ch-5whp
Third Party Advisory
https://www.wordfence.com/threat-intel/vulnerabilities/id/6ff76d9b-aa12-4391-90cd-f9df36d4a3a5
Third Party Advisory