Mastodon Mastodon Mastodon Mastodon

CVE-2026-87902: local file inclusion vulnerability in WordPress — who is affected and how to stay protected

Photo of author

CyberSecureFox Editorial Team

Published:

On September 22, 2026, WordPress released the emergency update 7.1.2, which fixes the critical vulnerability CVE-2026-87902 (CVSS 9.2) in the platform core. The vulnerability allows an unauthenticated attacker to force WordPress to include an arbitrary local PHP file located outside the active theme directories. If additional conditions are met on the server and theme side, this can lead to remote code execution (RCE). All versions from 4.7.0 to 7.1.1 are affected — administrators of WordPress sites should update immediately.

Technical essence of the vulnerability

The vulnerability is classified as CWE-98 — improper control of filename for PHP include. The issue lies in the get_page_template() function, which is responsible for selecting the page template file. Part of the filename is constructed from a URL path component, and in vulnerable versions WordPress did not apply a directory traversal check (path traversal via ../) to this value, even though the adjacent code already used such a check.

Since the filename is constructed using the page-{value}.php pattern, successful exploitation requires two prerequisites, listed in the official advisory:

  • The active theme (parent or child) contains a top-level directory whose name starts with page- (for example, page-templates). This condition is met by the legacy default themes Twenty Twelve and Twenty Fourteen, as well as a number of popular third-party themes — Neve, Hestia, Sydney.
  • There is a readable target PHP file on the server that the web server can include.

It is important to understand the two-level structure of the impact. Local file inclusion (LFI) itself is the first level: the attacker can force WordPress to include a PHP file that is already present on the server. The second level — escalation from LFI to full-fledged RCE — requires additional conditions. According to the advisory, one known path to RCE uses the pearcmd.php file from the PEAR package and depends on the PHP setting register_argc_argv, which is enabled by default in older PHP versions but disabled starting with PHP 8.5. The absence of pearcmd.php or a disabled register_argc_argv blocks this particular path to RCE but does not eliminate the underlying file inclusion vulnerability.

Affected versions and fixes

The vulnerability affects all WordPress branches from 4.7.0 through 7.1.1 inclusive. This means that even sites that updated to version 7.1.1 (released on September 17) remain vulnerable — CVE-2026-87902 is a separate issue from those fixed in that release.

The fix is available in WordPress 7.1.2 and has been backported to all supported branches down to 4.7.37. The full list of fixed versions by branch is published in the release notes.

Exploitation status: conflicting data

The situation with the exploitation status is ambiguous. Initial publications claimed that as of September 22 there was no public PoC exploit and no evidence of the vulnerability being used in attacks. However, the public repository of the researcher Robert Ressl, who discovered the vulnerability, contains PoC code marked as verified in a lab environment on September 22 — the same day the patch was released. At the same time, the repository explicitly notes that the PoC reproduces one specific configuration and does not attempt to assess the prevalence of vulnerable installations.

As for reports of active exploitation in the wild, they are based on third-party companies’ telemetry and are not confirmed by independent primary sources. At the time of writing, the vulnerability has not been added to the CISA Known Exploited Vulnerabilities catalog. Nevertheless, the presence of a public PoC and the relative simplicity of exploitation (no authentication required) make prompt updating critically important.

Previously, we already analyzed a similar issue in the WordPress ecosystem — forced theme installation via link, where the attack vector was also related to manipulating theme components.

Impact assessment

The scale of the potential impact is determined by two factors. On the one hand, WordPress is the most widespread CMS in the world, and the vulnerability affects versions spanning several years. On the other hand, practical exploitability is limited by the set of prerequisites: not every theme contains a page-* directory, not every server has a suitable PHP file to include, and not every PHP configuration allows escalation to RCE.

The highest risk is faced by sites that use older default WordPress themes or popular third-party themes with a page-templates directory, run on servers with outdated PHP versions (where register_argc_argv is enabled by default), and have PEAR installed.

Recommendations

WordPress recommends updating immediately and does not offer alternative workarounds — updating is the only fix. Specific steps:

  • Update WordPress to version 7.1.2 (or the corresponding fixed version for your branch: 7.0.6, 6.9.9, 6.8.10, etc.) via the dashboard (Updates → Update Now) or by downloading the release from WordPress.org. Sites with automatic background updates enabled will receive the patch automatically.
  • Check the active theme for a top-level directory whose name starts with page-. This is not a fix, but an indicator of the degree of exposure.
  • Check theregister_argc_argvsetting in the PHP configuration. If it is enabled, this is an additional risk factor for escalation from LFI to RCE.
  • Conduct an audit for signs of suspicious activity, in particular unusual requests to page templates and directory traversal attempts in URLs.

The CVE-2026-87902 vulnerability combines the absence of authentication requirements with a wide range of affected versions and the availability of a public PoC. Even with this conditional exploitability, the only reliable action is to update to WordPress 7.1.2 or the corresponding fixed version of your branch, and to do so within hours, not days.


CyberSecureFox Editorial Team

The CyberSecureFox Editorial Team covers cybersecurity news, vulnerabilities, malware campaigns, ransomware activity, AI security, cloud security, and vendor security advisories. Articles are prepared using official advisories, CVE/NVD data, CISA alerts, vendor publications, and public research reports. Content is reviewed before publication and updated when new information becomes available.

Leave a Comment

This site uses Akismet to reduce spam. Learn how your comment data is processed.