WordPress released version 7.1.2 to fix critical vulnerability CVE-2026-87902 / GHSA-7hp8-65ch-5whp, an improper filename-validation flaw (CWE-98) in get_page_template(). Under specific server and active-theme conditions, an unauthenticated attacker can influence page-template resolution to include a readable local PHP file outside the active theme directory, potentially resulting in remote code execution.
Exploitation requires the top-level directory for the selected template to begin with page-, a condition reported in the Twenty Twelve and Twenty Fourteen themes as well as some third-party themes. The flaw carries a CVSS score of 9.2; administrators should update immediately to 7.1.2 or ensure automatic updates are enabled. Fixes are also being backported to security-supported WordPress releases from version 4.7 onward.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
The CVE-2026-87902 Nuclei YAML template was revised to document and detect URL-encoded traversal through the WordPress pagename parameter, which can reach wp-links-opml.php via template resolution. The refactor improved the template's description, impact, remediation, flow, and matchers.
A ProjectDiscovery Nuclei Templates pull request added a template for WordPress CVE-2026-87902, characterized as a path-traversal issue. GitHub Actions assigned DhiyaneshGeek and requested review from theamanrawat for commit abfe901.
WordPress released version 7.1.2 to remediate CVE-2026-87902 (GHSA-7hp8-65ch-5whp), a critical improper filename-validation flaw in get_page_template() with a reported CVSS score of 9.2. Under required server and theme conditions, an unauthenticated attacker could include a readable local PHP file outside active theme directories, potentially enabling remote code execution; WordPress also began backporting fixes to supported branches through version 4.7.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
5 references tracked. Mallory keeps watching after this page renders.
heise.de
Open sourcethehackernews.com
Open sourcewordpress.org
Open sourcegithub.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.