CVE-2026-87902
WordPress core unauthenticated local file inclusion - get_page_template() resolves a page template outside the active theme and includes a chosen readable local .php file
- Severity
- critical
- Affected product
- WordPress
- Affected versions
- WordPress ≥ 7.1, < 7.1.2
- Affected versions
- WordPress ≥ 7.0, < 7.0.6
- Affected versions
- WordPress ≥ 6.9, < 6.9.9
- Affected versions
- WordPress ≥ 6.8, < 6.8.10
- Affected versions
- WordPress ≥ 6.7, < 6.7.9
- Affected versions
- WordPress ≥ 6.6, < 6.6.9
- Affected versions
- WordPress ≥ 6.5, < 6.5.12
- Affected versions
- WordPress ≥ 6.4, < 6.4.12
- Affected versions
- WordPress ≥ 6.3, < 6.3.12
- Affected versions
- WordPress ≥ 6.2, < 6.2.13
- Affected versions
- WordPress ≥ 6.1, < 6.1.14
- Affected versions
- WordPress ≥ 6.0, < 6.0.16
- Affected versions
- WordPress ≥ 5.9, < 5.9.18
- Affected versions
- WordPress ≥ 5.8, < 5.8.17
- Affected versions
- WordPress ≥ 5.7, < 5.7.19
- Affected versions
- WordPress ≥ 5.6, < 5.6.21
- Affected versions
- WordPress ≥ 5.5, < 5.5.22
- Affected versions
- WordPress ≥ 5.4, < 5.4.23
- Affected versions
- WordPress ≥ 5.3, < 5.3.25
- Affected versions
- WordPress ≥ 5.2, < 5.2.28
- Affected versions
- WordPress ≥ 5.1, < 5.1.26
- Affected versions
- WordPress ≥ 5.0, < 5.0.29
- Affected versions
- WordPress ≥ 4.9, < 4.9.33
- Affected versions
- WordPress ≥ 4.8, < 4.8.32
- Affected versions
- WordPress ≥ 4.7, < 4.7.37
- Fixed in
- WordPress 7.1.2
- Fixed in
- WordPress 7.0.6
- Fixed in
- WordPress 6.9.9
- Fixed in
- WordPress 6.8.10
- Fixed in
- WordPress 6.7.9
- Fixed in
- WordPress 6.6.9
- Fixed in
- WordPress 6.5.12
- Fixed in
- WordPress 6.4.12
- Fixed in
- WordPress 6.3.12
- Fixed in
- WordPress 6.2.13
- Fixed in
- WordPress 6.1.14
- Fixed in
- WordPress 6.0.16
- Fixed in
- WordPress 5.9.18
- Fixed in
- WordPress 5.8.17
- Fixed in
- WordPress 5.7.19
- Fixed in
- WordPress 5.6.21
- Fixed in
- WordPress 5.5.22
- Fixed in
- WordPress 5.4.23
- Fixed in
- WordPress 5.3.25
- Fixed in
- WordPress 5.2.28
- Fixed in
- WordPress 5.1.26
- Fixed in
- WordPress 5.0.29
- Fixed in
- WordPress 4.9.33
- Fixed in
- WordPress 4.8.32
- Fixed in
- WordPress 4.7.37
- Added to NewScan
- 2026-09-26
- Detected by
- NewScan — free, self-hosted
How NewScan reports it
COMPONENT VERSION RANGE
NewScan fingerprints WordPress from its response and reports this CVE when the detected version falls inside the affected range below.
Added 2026-09-26 (/daily-cve) from CISA KEV; CVSS v4.0 9.2, EPSS 3%, and Patchstack reports sites being probed within hours of the patch. This note covers all 25 branch rows below it. VERSION-MATCH ONLY, and the reason is in the CVSS vector: AT:P (attack requirements present). Exploitation needs the active theme to own a top-level directory whose name starts with `page-` AND a readable .php target on the box (the pearcmd.php shape) AND the server config that makes including it useful - none of which an anonymous prober can establish, and the probe that would try is an arbitrary local include against a customer's site. PER-BRANCH RANGES, NOT A FLAT `lt`, and that is the whole design of this row set: the advisory says 'versions 4.7.0 through 7.1.1' but WordPress backported the fix to all 25 branches still eligible for security fixes, so `lt: 7.1.2` alone would report every patched 6.9.9 / 6.8.10 / 5.9.18 install as vulnerable - a false positive on an up-to-date site, which section 5b calls worse than no gate. CVE-2026-64638 hit this exact wall on 2026-08-08 and had to be narrowed to one branch because WordPress had not published the backport numbers yet; here they ARE published, branch by branch, so all 25 are written and the row set is complete instead of deliberately partial. The floors are two-part ('6.9', not '6.9.0') on purpose: WordPress's generator meta names its .0 release '6.9', and techdb._branch_label suppresses a version shorter than its own `ge` floor, so a three-part floor would silently drop every .0 release in the set. Double-digit patch levels (6.8.10, 5.6.21, 4.7.37) are why this can only be a numeric comparison - techdb.parse_version tuples them, so 6.8.9 < 6.8.10 holds. OBSERVATION SOURCE, named: wordpress_tools.mine_wp_version reads the core version from the generator meta tag, a core asset's ?ver=, the RSS feed generator, /readme.html or a comment/JS, in that order, and scan_wordpress joins it onto this key via _record_cves - the same route the four WordPress rows above already ride.
COMPONENT VERSION RANGE
NewScan fingerprints WordPress from its response and reports this CVE when the detected version falls inside the affected range below.
COMPONENT VERSION RANGE
NewScan fingerprints WordPress from its response and reports this CVE when the detected version falls inside the affected range below.
COMPONENT VERSION RANGE
NewScan fingerprints WordPress from its response and reports this CVE when the detected version falls inside the affected range below.
COMPONENT VERSION RANGE
NewScan fingerprints WordPress from its response and reports this CVE when the detected version falls inside the affected range below.
COMPONENT VERSION RANGE
NewScan fingerprints WordPress from its response and reports this CVE when the detected version falls inside the affected range below.
COMPONENT VERSION RANGE
NewScan fingerprints WordPress from its response and reports this CVE when the detected version falls inside the affected range below.
COMPONENT VERSION RANGE
NewScan fingerprints WordPress from its response and reports this CVE when the detected version falls inside the affected range below.
COMPONENT VERSION RANGE
NewScan fingerprints WordPress from its response and reports this CVE when the detected version falls inside the affected range below.
COMPONENT VERSION RANGE
NewScan fingerprints WordPress from its response and reports this CVE when the detected version falls inside the affected range below.
COMPONENT VERSION RANGE
NewScan fingerprints WordPress from its response and reports this CVE when the detected version falls inside the affected range below.
COMPONENT VERSION RANGE
NewScan fingerprints WordPress from its response and reports this CVE when the detected version falls inside the affected range below.
COMPONENT VERSION RANGE
NewScan fingerprints WordPress from its response and reports this CVE when the detected version falls inside the affected range below.
COMPONENT VERSION RANGE
NewScan fingerprints WordPress from its response and reports this CVE when the detected version falls inside the affected range below.
COMPONENT VERSION RANGE
NewScan fingerprints WordPress from its response and reports this CVE when the detected version falls inside the affected range below.
COMPONENT VERSION RANGE
NewScan fingerprints WordPress from its response and reports this CVE when the detected version falls inside the affected range below.
COMPONENT VERSION RANGE
NewScan fingerprints WordPress from its response and reports this CVE when the detected version falls inside the affected range below.
COMPONENT VERSION RANGE
NewScan fingerprints WordPress from its response and reports this CVE when the detected version falls inside the affected range below.
COMPONENT VERSION RANGE
NewScan fingerprints WordPress from its response and reports this CVE when the detected version falls inside the affected range below.
COMPONENT VERSION RANGE
NewScan fingerprints WordPress from its response and reports this CVE when the detected version falls inside the affected range below.
COMPONENT VERSION RANGE
NewScan fingerprints WordPress from its response and reports this CVE when the detected version falls inside the affected range below.
COMPONENT VERSION RANGE
NewScan fingerprints WordPress from its response and reports this CVE when the detected version falls inside the affected range below.
COMPONENT VERSION RANGE
NewScan fingerprints WordPress from its response and reports this CVE when the detected version falls inside the affected range below.
COMPONENT VERSION RANGE
NewScan fingerprints WordPress from its response and reports this CVE when the detected version falls inside the affected range below.
COMPONENT VERSION RANGE
NewScan fingerprints WordPress from its response and reports this CVE when the detected version falls inside the affected range below.
References
Scan for this yourself — local, in-band scanning is free.
Get NewScan (FREE) →