All verified exploits

CVE-2026-87902 Unauthenticated Page-Template Path Traversal (LFI to RCE)

Deterministic critical WordPress CISA KEV Added cve-verified-cve-2026-87902

Detects WordPress sites where an unauthenticated visitor can make the page-template loader execute a PHP file from outside the theme. WordPress 4.7.0 through 7.1.1 build a template candidate from the requested page slug without validating it, and the only sanitiser applied to that slug deliberately preserves percent-escaped characters, so a double-encoded traversal survives and is decoded straight back into a directory path. If the active theme owns a top-level directory whose name starts with page- (page-templates in Twenty Twelve, Twenty Fourteen, Neve, Hestia and Sydney) the traversal climbs out of the theme and any readable .php file on the server is included. The verifier proves it by making the site return the output of its own wp-links-opml.php from a normal page URL, with a benign slug as the control. Attackers are already chaining the same primitive into PEAR pearcmd.php to write attacker-controlled PHP to disk, which is remote code execution. CVSS 9.2, CISA KEV, exploited in the wild within hours of the patch. Upgrade to WordPress 7.1.2, or the patched release on your branch (backported as far as 4.7.37).

Related WordPress exploits

Is your app exploitable through CVE-2026-87902?

Scan your domain free