CVE-2026-87902
EUVD-2026-8455522.09.2026, 17:17
An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the active theme directories. If relevant pre-conditions for both the server and the active theme are met, this can lead to RCE.
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| wordpress | wordpress | 𝑥 < 7.1.2 | CNA |
Debian Releases
Vulnerability Media Exposure