WordPress CVE-2026-87902: A Page-Template Bug in Every Release Since 4.7, Patched in 7.1.2
Security / news
WordPress CVE-2026-87902: A Page-Template Bug in Every Release Since 4.7, Patched in 7.1.2
The 9.2 rating describes a file include; code execution needs a theme folder starting with page- and a PHP setting, but probes began five hours after the patch.

An unauthenticated visitor can make WordPress's get_page_template() include a readable PHP file from outside the active theme's folders. On sites that meet three further conditions, that becomes remote code execution. WordPress's advisory GHSA-7hp8-65ch-5whp tracks it as CVE-2026-87902, rated 9.2 on CVSS v4, and covers every release from 4.7.0 through 7.1.1.
CISA added the flaw to its Known Exploited Vulnerabilities (KEV) catalog on September 25 with a September 28 due date. The advisory documents no workaround, so the only remedy is to update.
Patched versions
WordPress shipped 7.1.2 on September 22 and backported the fix to every maintained branch back to 4.7. The advisory lists 25 fixed releases, including these:
| Branch | Fixed version |
|---|---|
| 7.1 | 7.1.2 |
| 7.0 | 7.0.6 |
| 6.9 | 6.9.9 |
| 6.8 | 6.8.10 |
| 5.0 | 5.0.29 |
| 4.7 | 4.7.37 |
Sites that pin core versions are the ones to check first.

What has to be true for code execution
The score describes the file include. The advisory's preconditions for execution are narrower:
- The active theme contains a directory whose name starts with
page-. The advisory names Twenty Twelve, Twenty Fourteen, Neve, Hestia and Sydney as examples. - A readable
.phpfile exists on the server that does something useful when included. The public proof of concept uses PEAR'spearcmd.php. - PHP's
register_argc_argvis on.
The advisory says official PHP Docker images and cPanel defaults, on PHP versions before 8.5, meet the PEAR conditions. The score overstates the risk for a site on a theme without a page- folder, and understates it for a container built from a stock PHP image.
The timeline
SOC Prime's reconstruction gives these dates, with the researcher Robert Ressl credited as discoverer:
- July 20: Ressl reports the flaw privately through HackerOne.
- July 21: WordPress acknowledges the report.
- September 15: WordPress tells Ressl a fix is planned.
- September 22: advisory, patch and a public proof of concept appear together.
- September 25: CISA lists the flaw.
Patchstack reported probing at about 17:44 UTC on September 22, under five hours after 7.1.2 became available. SOC Prime's account says the traffic was probing rather than successful payload delivery, and that the requests targeted ordinary WordPress core PHP files. CISA's catalog adds only flaws it has evidence are exploited, so the September 25 listing suggests the probing was followed by something more, though the sources I read do not describe what.
Nobody has published a count of compromised sites. The proof of concept shipped the same day as the patch.
What to do
Update to the fixed version for the installed branch and confirm the version in the dashboard. Where an update must wait, check whether the theme has a page- directory and whether register_argc_argv is enabled. Look for unexpected PHP files in upload and cache directories.
Our reporting on another entry with a three-day KEV clock is in the Zammad session-fixation piece, and Denmark's 8.8 million-record CPR breach shows what is at stake when personal data sits on an exposed service, though it is unrelated to this flaw.
The September 28 federal deadline has passed.
Sources
More in Security
- 01Pwn2Own Ireland 2026 Day One: Seven of 20 Listed Entries Were Collisions, and OpenAI Codex Fell to Argument InjectionSamsung's Galaxy S26 was hit three times, Sonos and Philips Hue each twice or more, and a Google Pixel 10 attempt ran out of time. Vendors get 90 days before details go public.
- 02Atlassian CVE-2026-21589: A 9.3 File-Access Flaw Hits Every Data Center Version of Eight ProductsAn unauthenticated request can read a file from the web root if the attacker already knows its exact path. Atlassian reports no exploitation and has released fixes for each product line.
- 03Citrix's September 27 NetScaler Fix Does Not Cover CVE-2026-88779, Now on CISA's Exploited ListBuilds that closed two exploited zero-days stay vulnerable to a SAML flaw that CISA added on October 4 with a three-day deadline.
- 04FortiMail CVE-2026-104286: Exploited 9.8 Flaw Lets Unauthenticated Requests Write FilesFortinet's advisory lists a workaround and fixed builds for three release branches; the 7.2 branch gets none.