← All CVEs NewScan detects
critical

CVE-2026-87902

WordPress core unauthenticated local file inclusion - get_page_template() resolves a page template outside the active theme and includes a chosen readable local .php file

Severity
critical
Affected product
WordPress
Affected versions
WordPress ≥ 7.1, < 7.1.2
Affected versions
WordPress ≥ 7.0, < 7.0.6
Affected versions
WordPress ≥ 6.9, < 6.9.9
Affected versions
WordPress ≥ 6.8, < 6.8.10
Affected versions
WordPress ≥ 6.7, < 6.7.9
Affected versions
WordPress ≥ 6.6, < 6.6.9
Affected versions
WordPress ≥ 6.5, < 6.5.12
Affected versions
WordPress ≥ 6.4, < 6.4.12
Affected versions
WordPress ≥ 6.3, < 6.3.12
Affected versions
WordPress ≥ 6.2, < 6.2.13
Affected versions
WordPress ≥ 6.1, < 6.1.14
Affected versions
WordPress ≥ 6.0, < 6.0.16
Affected versions
WordPress ≥ 5.9, < 5.9.18
Affected versions
WordPress ≥ 5.8, < 5.8.17
Affected versions
WordPress ≥ 5.7, < 5.7.19
Affected versions
WordPress ≥ 5.6, < 5.6.21
Affected versions
WordPress ≥ 5.5, < 5.5.22
Affected versions
WordPress ≥ 5.4, < 5.4.23
Affected versions
WordPress ≥ 5.3, < 5.3.25
Affected versions
WordPress ≥ 5.2, < 5.2.28
Affected versions
WordPress ≥ 5.1, < 5.1.26
Affected versions
WordPress ≥ 5.0, < 5.0.29
Affected versions
WordPress ≥ 4.9, < 4.9.33
Affected versions
WordPress ≥ 4.8, < 4.8.32
Affected versions
WordPress ≥ 4.7, < 4.7.37
Fixed in
WordPress 7.1.2
Fixed in
WordPress 7.0.6
Fixed in
WordPress 6.9.9
Fixed in
WordPress 6.8.10
Fixed in
WordPress 6.7.9
Fixed in
WordPress 6.6.9
Fixed in
WordPress 6.5.12
Fixed in
WordPress 6.4.12
Fixed in
WordPress 6.3.12
Fixed in
WordPress 6.2.13
Fixed in
WordPress 6.1.14
Fixed in
WordPress 6.0.16
Fixed in
WordPress 5.9.18
Fixed in
WordPress 5.8.17
Fixed in
WordPress 5.7.19
Fixed in
WordPress 5.6.21
Fixed in
WordPress 5.5.22
Fixed in
WordPress 5.4.23
Fixed in
WordPress 5.3.25
Fixed in
WordPress 5.2.28
Fixed in
WordPress 5.1.26
Fixed in
WordPress 5.0.29
Fixed in
WordPress 4.9.33
Fixed in
WordPress 4.8.32
Fixed in
WordPress 4.7.37
Added to NewScan
2026-09-26
Detected by
NewScan — free, self-hosted

How NewScan reports it

COMPONENT VERSION RANGE

NewScan fingerprints WordPress from its response and reports this CVE when the detected version falls inside the affected range below.

Added 2026-09-26 (/daily-cve) from CISA KEV; CVSS v4.0 9.2, EPSS 3%, and Patchstack reports sites being probed within hours of the patch. This note covers all 25 branch rows below it. VERSION-MATCH ONLY, and the reason is in the CVSS vector: AT:P (attack requirements present). Exploitation needs the active theme to own a top-level directory whose name starts with `page-` AND a readable .php target on the box (the pearcmd.php shape) AND the server config that makes including it useful - none of which an anonymous prober can establish, and the probe that would try is an arbitrary local include against a customer's site. PER-BRANCH RANGES, NOT A FLAT `lt`, and that is the whole design of this row set: the advisory says 'versions 4.7.0 through 7.1.1' but WordPress backported the fix to all 25 branches still eligible for security fixes, so `lt: 7.1.2` alone would report every patched 6.9.9 / 6.8.10 / 5.9.18 install as vulnerable - a false positive on an up-to-date site, which section 5b calls worse than no gate. CVE-2026-64638 hit this exact wall on 2026-08-08 and had to be narrowed to one branch because WordPress had not published the backport numbers yet; here they ARE published, branch by branch, so all 25 are written and the row set is complete instead of deliberately partial. The floors are two-part ('6.9', not '6.9.0') on purpose: WordPress's generator meta names its .0 release '6.9', and techdb._branch_label suppresses a version shorter than its own `ge` floor, so a three-part floor would silently drop every .0 release in the set. Double-digit patch levels (6.8.10, 5.6.21, 4.7.37) are why this can only be a numeric comparison - techdb.parse_version tuples them, so 6.8.9 < 6.8.10 holds. OBSERVATION SOURCE, named: wordpress_tools.mine_wp_version reads the core version from the generator meta tag, a core asset's ?ver=, the RSS feed generator, /readme.html or a comment/JS, in that order, and scan_wordpress joins it onto this key via _record_cves - the same route the four WordPress rows above already ride.

COMPONENT VERSION RANGE

NewScan fingerprints WordPress from its response and reports this CVE when the detected version falls inside the affected range below.

COMPONENT VERSION RANGE

NewScan fingerprints WordPress from its response and reports this CVE when the detected version falls inside the affected range below.

COMPONENT VERSION RANGE

NewScan fingerprints WordPress from its response and reports this CVE when the detected version falls inside the affected range below.

COMPONENT VERSION RANGE

NewScan fingerprints WordPress from its response and reports this CVE when the detected version falls inside the affected range below.

COMPONENT VERSION RANGE

NewScan fingerprints WordPress from its response and reports this CVE when the detected version falls inside the affected range below.

COMPONENT VERSION RANGE

NewScan fingerprints WordPress from its response and reports this CVE when the detected version falls inside the affected range below.

COMPONENT VERSION RANGE

NewScan fingerprints WordPress from its response and reports this CVE when the detected version falls inside the affected range below.

COMPONENT VERSION RANGE

NewScan fingerprints WordPress from its response and reports this CVE when the detected version falls inside the affected range below.

COMPONENT VERSION RANGE

NewScan fingerprints WordPress from its response and reports this CVE when the detected version falls inside the affected range below.

COMPONENT VERSION RANGE

NewScan fingerprints WordPress from its response and reports this CVE when the detected version falls inside the affected range below.

COMPONENT VERSION RANGE

NewScan fingerprints WordPress from its response and reports this CVE when the detected version falls inside the affected range below.

COMPONENT VERSION RANGE

NewScan fingerprints WordPress from its response and reports this CVE when the detected version falls inside the affected range below.

COMPONENT VERSION RANGE

NewScan fingerprints WordPress from its response and reports this CVE when the detected version falls inside the affected range below.

COMPONENT VERSION RANGE

NewScan fingerprints WordPress from its response and reports this CVE when the detected version falls inside the affected range below.

COMPONENT VERSION RANGE

NewScan fingerprints WordPress from its response and reports this CVE when the detected version falls inside the affected range below.

COMPONENT VERSION RANGE

NewScan fingerprints WordPress from its response and reports this CVE when the detected version falls inside the affected range below.

COMPONENT VERSION RANGE

NewScan fingerprints WordPress from its response and reports this CVE when the detected version falls inside the affected range below.

COMPONENT VERSION RANGE

NewScan fingerprints WordPress from its response and reports this CVE when the detected version falls inside the affected range below.

COMPONENT VERSION RANGE

NewScan fingerprints WordPress from its response and reports this CVE when the detected version falls inside the affected range below.

COMPONENT VERSION RANGE

NewScan fingerprints WordPress from its response and reports this CVE when the detected version falls inside the affected range below.

COMPONENT VERSION RANGE

NewScan fingerprints WordPress from its response and reports this CVE when the detected version falls inside the affected range below.

COMPONENT VERSION RANGE

NewScan fingerprints WordPress from its response and reports this CVE when the detected version falls inside the affected range below.

COMPONENT VERSION RANGE

NewScan fingerprints WordPress from its response and reports this CVE when the detected version falls inside the affected range below.

COMPONENT VERSION RANGE

NewScan fingerprints WordPress from its response and reports this CVE when the detected version falls inside the affected range below.

References

Scan for this yourself — local, in-band scanning is free.

Get NewScan (FREE) →