CVE-2026-87902 in WordPress Enables Conditional RCE
WordPress patches CVE-2026-87902, an unauthenticated path traversal that can enable conditional remote code execution.
WordPress security updates address CVE-2026-87902, described as a severe unauthenticated path traversal in the page-template resolution mechanism. The weakness can enable conditional remote code execution. The report does not say the flaw is being exploited in the wild.
- CVE-2026-87902 is an unauthenticated path traversal in WordPress page-template resolution.
- The flaw can enable conditional remote code execution.
- Security updates were released; in-the-wild exploitation is not stated.
Vulnerabilities mentionedAll →
- CVE-2026-879028.118%Unauthenticated Local File Inclusion to RCE in WordPress Core (fixed in 7.1.2)published · WordPress (WordPress.org) WordPress core KEV PoC ×16
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected |
|---|
CVE-2026-87902 in WordPress Enables Conditional RCE Security updates released for WordPress address CVE-2026-87902 , a severe unauthenticated path traversal flaw within its page-template resolution mechanism. The weaknes
The full text could not be extracted from this site (paywall, bot protection or heavy scripting). Read it at socradar.io.