CVE-2026-87902: WordPress Core Remote File Inclusion Vulnerability

High severity, CVSS 8.1. Actively exploited: in CISA KEV since 2026-09-25. EPSS: 40% chance of exploitation in the next 30 days.

An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the active theme directories. If relevant pre-conditions for both the server and the active theme are met, this can lead to RCE.

Affected products

  • WordPress WordPress: before 4.7.37 (fixed in 4.7.37); from 4.8, before 4.8.32 (fixed in 4.8.32); from 4.9, before 4.9.33 (fixed in 4.9.33); from 5.0, before 5.0.29 (fixed in 5.0.29); from 5.1, before 5.1.26 (fixed in 5.1.26); from 5.2, before 5.2.28 (fixed in 5.2.28); …

Published 2026-09-22. Last modified 2026-09-28.