cve-2026-87902

HIGH CVSS 8.1 euvd_kev
Description

An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the active theme directories. If relevant pre-conditions for both the server and the active theme are met, this can lead to RCE.

Timeline
Published
Sep 22, 2026, 4:44:15 PM
Last Modified
Sep 26, 2026, 3:55:51 AM
CVSS Details

CVSS details not available.

Affected Products

No product information available.

References

No references available.

Linked Vulnerabilities

{
  "aliases": "CVE-2026-87902\n",
  "cvss": 8.1,
  "datePublished": "Sep 22, 2026, 4:44:15 PM",
  "dateUpdated": "Sep 26, 2026, 3:55:51 AM",
  "description": "An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the active theme directories. If relevant pre-conditions for both the server and the active theme are met, this can lead to RCE.",
  "euvdId": "EUVD-2026-84555",
  "exploitedSince": "Sep 23, 2026, 12:00:00 AM",
  "id": "CVE-2026-87902",
  "kev_catalogs": [
    "euvd"
  ],
  "severity": "HIGH",
  "source": "euvd_kev",
  "title": "EUVD-2026-84555"
}
Enrichment data
View JSON API Download JSON