cve-2026-87902
HIGH CVSS 8.1 euvd_kev
Description
An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the active theme directories. If relevant pre-conditions for both the server and the active theme are met, this can lead to RCE.
Timeline
- Published
- Sep 22, 2026, 4:44:15 PM
- Last Modified
- Sep 26, 2026, 3:55:51 AM
CVSS Details
CVSS details not available.
Affected Products
No product information available.
References
No references available.
Linked Vulnerabilities
{
"aliases": "CVE-2026-87902\n",
"cvss": 8.1,
"datePublished": "Sep 22, 2026, 4:44:15 PM",
"dateUpdated": "Sep 26, 2026, 3:55:51 AM",
"description": "An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the active theme directories. If relevant pre-conditions for both the server and the active theme are met, this can lead to RCE.",
"euvdId": "EUVD-2026-84555",
"exploitedSince": "Sep 23, 2026, 12:00:00 AM",
"id": "CVE-2026-87902",
"kev_catalogs": [
"euvd"
],
"severity": "HIGH",
"source": "euvd_kev",
"title": "EUVD-2026-84555"
}
Enrichment data
Aggregated bundle (all enrichments)