criticalCVE-2026-87902CVSS 9.2
WordPress Core - PHP Template Path Traversal
Could this critical WordPress vulnerability affect your website?
An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the active theme directories. If relevant pre-conditions for both the server and the active theme are met, this can lead to RCE.
Enter a domain you own and we will test it right now — and, while we are there, report anything else it exposes publicly. No account, no agent to install.
Recommended remediation
Update WordPress to a patched maintenance release for the installed branch.
Tags
cvecve2026wordpresswp-corelfiunauth