Vulnerabilities

WordPress CVE-2026-87902: check and install the security update

WordPress released fixes for path traversal in page-template resolution that can lead to code execution under specific conditions.

Conceptual illustration: WordPress CVE-2026-87902: check and install the security update
Conceptual illustration · SecurCheck

What is confirmed

The official advisory describes CVE-2026-87902: an unauthenticated attacker can influence template resolution to include a readable local PHP file outside the active theme.

Remote code execution requires particular environment and theme conditions. WordPress released version 7.1.2 on 22 September and fixes for multiple older branches.

What it means

Running an affected version warrants patching but does not prove a site was already compromised.

An external check can surface reputation indicators but cannot replace an inventory of WordPress core, theme and server logs.

What to do

Check your version under Dashboard → Updates, back up the site, then install the patched release for your branch or the latest supported version.

If you see signs of compromise, review theme files, administrator accounts and logs with your host or security team.

Check a suspicious sign

Use the related SecurCheck tool, then confirm important decisions with an official source.

Sources

  1. WordPress — avis GHSA-7hp8-65ch-5whp
  2. WordPress.org — version 7.1.2