CVE-2026-87902 – Critical WordPress Remote File Inclusion Vulnerability
Key Takeaways:
- CVE-2026-87902 is a Critical unauthenticated remote file inclusion vulnerability in WordPress.
- Attackers can include arbitrary PHP files, leading to RCE under specific theme and server conditions.
- Affects WordPress versions 4.7.0 – 7.1.1; fixed in 7.1.2 and 4.7.37.
- Already in the CISA KEV with observed active exploitation.
- Immediate action: patch to the latest version or apply workarounds.
CVE-2026-87902 is a Critical vulnerability in WordPress that allows unauthenticated attackers to include arbitrary files on the server, potentially resulting in remote code execution. The flaw, which has been added to the CISA Known Exploited Vulnerabilities (KEV) catalog, is being actively exploited in the wild, making it a top priority for defenders.
Overview
The vulnerability resides in the get_page_template() function, which resolves page templates based on user-supplied input. An attacker can craft a request that forces the application to include a readable PHP file outside the active theme directories. If specific server and theme pre-conditions are met—such as the presence of a file like pearcmd.php and the register_argc_argv setting enabled—this can escalate to full remote code execution.
Because the attack requires no authentication and has a relatively high CVSS score, it poses a significant threat to any internet-facing WordPress site running an affected version.
Technical Details
The root cause is an improper control of filename for input/output (CWE-98). The vulnerable code path is triggered when get_page_template() processes a request and passes the result to locate_template(), which includes the file without adequate theme-root jail.
In practice, an attacker can send a request such as:
GET /?page_id=../../path/to/pearcmd.php HTTP/1.1
If the server configuration allows PHP execution in the targeted directory and the theme supports the inclusion, the attacker can achieve code execution as the web server user. Public proof-of-concept exploits have been released, and threat actors have begun weaponizing the flaw within hours of disclosure.
Severity & Impact
The vulnerability scores 8.1 HIGH on the CVSS v3.1 scale with the following vector:
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- Attack Vector: Network
- Attack Complexity: High
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact: High impact on confidentiality, integrity, and availability
The presence of this vulnerability in the CISA KEV indicates that it is being actively exploited in real-world attacks. Organizations should treat it as an urgent remediation priority.
Affected Products
The vulnerability affects WordPress versions 4.7.0 through 7.1.1. The fix has been released in version 7.1.2 and backported to 4.7.37.
For the full list of affected products and versions, see the CVE-2026-87902 page on VulnSocial.
Actionable Insights / What to Do
- Confirm exposure: Check your WordPress version against the affected range. If you are running any version between 4.7.0 and 7.1.1, you are vulnerable.
- Monitor for signs of exploitation: Look for unusual requests containing path traversal sequences, unexpected PHP files (especially
pearcmd.php), or spikes in traffic to page template endpoints. - **Prioritize patching: Given the active exploitation and CISA KEV listing, apply the patch as soon as possible.
- **If patching is delayed: Implement temporary workarounds such as blocking access to the vulnerable endpoint via a WAF rule or disabling the affected theme.
Remediation & Mitigation
- **Update WordPress: Upgrade to version 7.1.2 or later, or apply the backported fix for 4.7.37. Always test updates in a staging environment first.
- Apply WAF rules: If available, enable rules that block path traversal attempts and the inclusion of suspicious files. (See reference links for vendor-specific guidance.)
- Audit your site: After **patching, scan for unauthorized PHP files, check file modification times, and review user accounts for any created by an attacker.
- Enable file integrity monitoring: Use tools that alert on changes to core WordPress files and theme directories.
- Harden server configuration: Ensure
register_argc_argvis disabled if not needed, and restrict PHP execution in writable directories.
References
- WordPress Security Advisory GHSA-7hp8-65ch-5whp
- PatchStack: CVE-2026-87902 Attackers Started Probing WordPress Sites Hours After the Patch
- CISA Known Exploited Vulnerabilities Catalog – CVE-2026-87902
- VulnSocial CVE-2026-87902 (for live threat activity and timeline)
Bottom Line
CVE-2026-87902 is a **Critical, unauthenticated file inclusion vulnerability in WordPress that is being actively exploited in the wild. With a CVSS score of 8.1 HIGH and a place in the CISA KEV, it demands immediate attention. Update to the fixed version now, and if you cannot, apply workarounds and monitor your environment closely.
#CVE202687902 #WordPress #RCE #CISAKEV #Critical
