Search

Find merged stories by title or summary.

Vulnerabilities & Patches
Emerging1 src

Hackers start exploiting critical WordPress flaw for code execution

Threat actors have moved from probing WordPress sites vulnerable to CVE-2026-87902 to exploiting the flaw to write files to disk that execute shell commands when accessed. [... ]

·BleepingComputer
Read →
Vulnerabilities & Patches
Emerging1 src

Critical WordPress Core Flaw Lets Unauthenticated Attackers Execute Remote Code

WordPress has released version 7. 1. 2 to address a critical core vulnerability that could allow unauthenticated attackers to achieve remote code execution under specific server and theme configurations. Tracked as CVE-2026-87902 and GHSA-7hp8-65ch-5whp, the flaw carries a CVSS v4 score of 9. 2 and affects WordPress installations dating back to version 4. 7. The issue resides in WordPress page-template resolution, specifically within the get_page_template() functionality. An attacker does not need a WordPress account or any privileges to exploit the flaw. Critical WordPress Core Flaw By manipulating page-template handling, they may be able to cause WordPress to include a readable local PHP file located outside the active theme directory.

·CyberPress
Read →
Vulnerabilities & Patches
Emerging1 src

WordPress 7.1.2 fixes critical unauthenticated path traversal vulnerability (CVE-2026-87902)

WordPress released version 7. 1. 2 to fix a critical flaw that lets an unauthenticated attacker make the software load a PHP file of the attacker’s choosing from outside the site’s active theme folders. On sites where the server and the active theme meet certain conditions, the attacker can go on to run code on the server. The project tracks the flaw as CVE-2026-87902 and lists every release from 4. 7. 0 through 7. 1. 1 as affected. The attacker needs … More → The post WordPress 7. 1. 2 fixes critical unauthenticated path traversal vulnerability (CVE-2026-87902) appeared first on Help Net Security .

·Help Net Security
Read →
Vulnerabilities & Patches
Emerging1 src

CVE-2026-87902: how close is your WordPress to remote code execution?

WordPress 7. 1. 2 fixes an unauthenticated file inclusion bug active since version 4. 7, patchable but exploitable into remote code execution. WordPress 7. 1. 2 shipped on September 22 address an unauthenticated local file inclusion, tracked as CVE-2026-87902 (CVSS score of 9. 2), which stems of how the CMS resolves page templates, with a real path to remote code execution. The bugs affected every version back to 4. 7. 0. That’s nearly a decade of releases, and nobody needs an account to trigger it. Robert Ressl gets credit for reporting it. The flaw resides in get_page_template() , the function WordPress uses to choose which template should load a page. WordPress creates a list of possible template filenames, and one of them comes directly from the pagename value in the URL without any proper validation. The problem becomes clearer when you look at the code around it.

·Security Affairs
Read →
Vulnerabilities & Patches
Emerging1 src

NVD-CVE-2026-87902 - nvd.nist.gov

NVD-CVE-2026-87902 nvd. nist. gov

·NVD
Read →

You've reached the end of current stories for this search.