CVE-CVE-2026-87902
Severity
HIGH
CVSS Score
8.1
Description
An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the active theme directories. If relevant pre-conditions for both the server and the active theme are met, this can lead to RCE....
PoCs for CVE-CVE-2026-87902
cve-2026-87902-poc
RCE
Python
3
ressl
2026-09-22
CVE-2026-87902-Toolkit
RCE
Python
1
tc4dy
2026-09-23
CVE-2026-87902-PoC-pwnVader
General
Shell
0
pwnVader
2026-09-22
CVE-2026-87902-A-working-PoC-for-WordPress-s-critical-path-t...
RCE
0
rabakuku
2026-09-23
cve-2026-87902-wordpress-lfi-lab
RCE
Python
0
dinosn
2026-09-23
wordpress-cve-2026-87902
General
Python
0
nextco
2026-09-24
CVE-2026-87902
RCE
Python
0
Lutfifakee-Project
2026-09-23
EXPLOIT-CVE-2026-87902
RCE
Python
0
joaovicdev
2026-09-25
CVE-2026-87902_PoC
General
Python
0
khellwan
2026-09-25
CVE-2026-87902-exploit
General
Python
0
Maalfer
2026-09-27