{"aliases":"CVE-2026-87902\n","cvss":8.1,"datePublished":"Sep 22, 2026, 4:44:15 PM","dateUpdated":"Sep 26, 2026, 3:55:51 AM","description":"An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the active theme directories. If relevant pre-conditions for both the server and the active theme are met, this can lead to RCE.","euvdId":"EUVD-2026-84555","exploitedSince":"Sep 23, 2026, 12:00:00 AM","id":"CVE-2026-87902","kev_catalogs":["euvd"],"severity":"HIGH","source":"euvd_kev","title":"EUVD-2026-84555"}