WordPress Core PHP Template Path Traversal
Unauthenticated path traversal in page-template resolution leading to conditional RCE
CVE-2026-87902
Fixed in:
- 7.1.2
- 7.0.6
- 6.9.9
- 6.8.10
- 6.7.9
- 6.6.9
- 6.5.12
- 6.4.12
- 6.3.12
- 6.2.13
- 6.1.14
- 6.0.16
- 5.9.18
- 5.8.17
- 5.7.19
- 5.6.21
- 5.5.22
- 5.4.23
- 5.3.25
- 5.2.28
- 5.1.26
- 5.0.29
- 4.9.33
- 4.8.32
- 4.7.37
https://lwn.net/Articles/1096195/
https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-7hp8-65ch-5whp
Post #22869
465