{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-87902","assignerOrgId":"36234546-b8fa-4601-9d6f-f4e334aa8ea1","state":"PUBLISHED","assignerShortName":"hackerone","dateReserved":"2026-09-09T15:00:00.574Z","datePublished":"2026-09-22T16:44:15.048Z","dateUpdated":"2026-09-26T03:55:51.560Z"},"containers":{"cna":{"descriptions":[{"lang":"en","value":"An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the active theme directories. If relevant pre-conditions for both the server and the active theme are met, this can lead to RCE."}],"affected":[{"defaultStatus":"unaffected","vendor":"WordPress","product":"WordPress","versions":[{"version":"0","status":"affected","lessThan":"7.1.2","versionType":"semver"}]}],"references":[{"url":"https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-7hp8-65ch-5whp"}],"problemTypes":[{"descriptions":[{"type":"CWE","lang":"en","cweId":"CWE-98","description":"CWE-98 Remote File Inclusion"}]}],"credits":[{"lang":"en","value":"Robert (ressl)","type":"finder"}],"workarounds":[{"lang":"en","value":"WordPress 7.1.2 has been released containing a fix for the vulnerability, and as a courtesy to users on older branches the fix has been backported to all branches back to 4.7."}],"providerMetadata":{"orgId":"36234546-b8fa-4601-9d6f-f4e334aa8ea1","shortName":"hackerone","dateUpdated":"2026-09-22T16:44:15.048Z"}},"adp":[{"metrics":[{"cvssV3_1":{"scope":"UNCHANGED","version":"3.1","baseScore":8.1,"attackVector":"NETWORK","baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","integrityImpact":"HIGH","userInteraction":"NONE","attackComplexity":"HIGH","availabilityImpact":"HIGH","privilegesRequired":"NONE","confidentialityImpact":"HIGH"}},{"other":{"type":"ssvc","content":{"timestamp":"2026-09-25T00:00:00+00:00","options":[{"Exploitation":"active"},{"Automatable":"no"},{"Technical Impact":"total"}],"role":"CISA Coordinator","version":"2.0.3","id":"CVE-2026-87902"}}},{"other":{"type":"kev","content":{"dateAdded":"2026-09-25","reference":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-87902"}}}],"references":[{"url":"https://patchstack.com/articles/cve-2026-87902-attackers-started-probing-wordpress-sites-hours-after-the-patch/","tags":["third-party-advisory"]},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-87902","tags":["government-resource"]}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-09-26T03:55:51.560Z"},"timeline":[{"time":"2026-09-25T00:00:00.000Z","lang":"en","value":"CVE-2026-87902 added to CISA KEV"}]}]}}