Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-87902

An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the active theme directories. If relevant pre-conditions for both the server and the active theme are met, this can lead to RCE.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.225
EPSS Ranking 97.6%
CVSS Severity
CVSS v3 Score 8.1
Proposed Action
WordPress Core contains a remote file inclusion vulnerability which could allow an unauthenticated attacker to make page-template resolution include a chosen readable local `.php` file outside the active theme directories, leading to remote code execution.
Ransomware Campaign
Unknown
Products affected by CVE-2026-87902


Contact Us

Shodan ® - All rights reserved