Desert Forge IT — Arizona IT · Field-tested tools & guidesFree consult →

CVE-2026-87902: WordPress Core File Inclusion to RCE, Exploited (Update to 7.1.2)

Critical CVE-2026-87902 — An unauthenticated bug in WordPress core's get_page_template() can include arbitrary PHP files and lead to remote code execution. Every version since 4.7 is affected and it's being exploited. Fixed versions for every branch and how to check your site.

Published 2026-10-08 · Last updated 2026-10-08

TL;DR: No login needed: a crafted URL makes WordPress load a PHP file of the attacker's choosing from outside the theme. With certain themes and common PHP setups, including Docker's official PHP image and default cPanel, that becomes full remote code execution. It affects every release since 4.7 (2016) and is on CISA's exploited list. Update to 7.1.2, or the patched release on your branch.

CVECVE-2026-87902 (GHSA-7hp8-65ch-5whp)
ComponentWordPress core, get_page_template() in wp-includes/template.php
TypeLocal file inclusion (CWE-98) → remote code execution
CVSS 4.09.2 Critical
Auth neededNone
AffectedWordPress 4.7.0 – 7.1.1
Fixed in7.1.2 (2026-09-22), with backports: 7.0.6, 6.9.9, 6.8.10, 6.7.9 … 4.7.37
Exploited?Yes, CISA KEV 2026-09-25

What the bug is

When WordPress shows a page, get_page_template() builds a list of template filenames to try, such as page-about.php and page.php. One of those names comes from the pagename value in the request, and it wasn’t validated. A crafted value can steer WordPress into including a .php file outside the theme directory.

Including an arbitrary existing PHP file becomes remote code execution when the right file is lying around. The reporter showed two conditions that together make it work:

  • Theme: the active theme (or its parent) has a top-level directory whose name starts with page-. Several popular themes do, including Twenty Twelve, Twenty Fourteen, Neve, Hestia, and Sydney.
  • Server: a usable PHP file is readable. The classic is PEAR’s pearcmd.php with register_argc_argv enabled, which is the default in Docker’s official PHP image and in default cPanel setups on PHP before 8.5.

Am I affected?

Check your version under Dashboard → Updates, or with WP-CLI:

wp core version

Then check the two RCE preconditions:

# Theme: any top-level "page-*" directory in the active theme or its parent?
wp theme list --status=active,parent --field=name
ls -d wp-content/themes/<theme>/page-*/ 2>/dev/null

# Server: is register_argc_argv on, and is pearcmd.php present?
php -i | grep register_argc_argv
find / -name pearcmd.php 2>/dev/null

Even if both checks come back clean, update. File inclusion bugs often find new gadgets after disclosure.

How to patch

Sites with automatic background updates (on by default for minor releases) should already have received the fix for their branch. Confirm. Don’t assume.

wp core update
wp core version
BranchFixedBranchFixed
7.17.1.26.46.4.12
7.07.0.66.36.3.12
6.96.9.96.26.2.13
6.86.8.106.16.1.14
6.76.7.96.06.0.16
6.66.6.95.x / 4.7–4.9see advisory (back to 4.7.37)
6.56.5.12

If you can’t update immediately

  • Set register_argc_argv = Off in php.ini (or your PHP-FPM pool) and restart PHP.
  • Remove PEAR if you don’t use it, or at least make pearcmd.php unreadable by the web server user.
  • Enable a WAF rule for CVE-2026-87902 if you use Wordfence, Patchstack, Cloudflare, or Sucuri.

Was my site hit?

  • Search access logs for unusual pagename= values containing ../ or encoded variants (%2e%2e), and for requests mentioning pearcmd.
  • Look for new PHP files in wp-content/uploads/, /tmp, or theme folders: find wp-content -name '*.php' -newer wp-config.php.
  • Check for admin users you didn’t create: wp user list --role=administrator.
  • Verify core files: wp core verify-checksums.

Sources

← Back to Knowledge Base

Want this handled for you?

Desert Forge IT patches, monitors, and backs up servers and networks for Phoenix-area businesses. We track advisories like this one so you don’t have to. Get a free consult and we’ll tell you what you’re exposed to.

Get a free security check →  ·  More security advisories