Critical CVE-2026-87902 — An unauthenticated bug in WordPress core's get_page_template() can include arbitrary PHP files and lead to remote code execution. Every version since 4.7 is affected and it's being exploited. Fixed versions for every branch and how to check your site.
Published 2026-10-08 · Last updated 2026-10-08
TL;DR: No login needed: a crafted URL makes WordPress load a PHP file of the attacker's choosing from outside the theme. With certain themes and common PHP setups, including Docker's official PHP image and default cPanel, that becomes full remote code execution. It affects every release since 4.7 (2016) and is on CISA's exploited list. Update to 7.1.2, or the patched release on your branch.
| CVE | CVE-2026-87902 (GHSA-7hp8-65ch-5whp) |
|---|---|
| Component | WordPress core, get_page_template() in wp-includes/template.php |
| Type | Local file inclusion (CWE-98) → remote code execution |
| CVSS 4.0 | 9.2 Critical |
| Auth needed | None |
| Affected | WordPress 4.7.0 – 7.1.1 |
| Fixed in | 7.1.2 (2026-09-22), with backports: 7.0.6, 6.9.9, 6.8.10, 6.7.9 … 4.7.37 |
| Exploited? | Yes, CISA KEV 2026-09-25 |
When WordPress shows a page, get_page_template() builds a list of template filenames to try, such as page-about.php and page.php. One of those names comes from the pagename value in the request, and it wasn’t validated. A crafted value can steer WordPress into including a .php file outside the theme directory.
Including an arbitrary existing PHP file becomes remote code execution when the right file is lying around. The reporter showed two conditions that together make it work:
page-. Several popular themes do, including Twenty Twelve, Twenty Fourteen, Neve, Hestia, and Sydney.pearcmd.php with register_argc_argv enabled, which is the default in Docker’s official PHP image and in default cPanel setups on PHP before 8.5.Check your version under Dashboard → Updates, or with WP-CLI:
wp core version
Then check the two RCE preconditions:
# Theme: any top-level "page-*" directory in the active theme or its parent?
wp theme list --status=active,parent --field=name
ls -d wp-content/themes/<theme>/page-*/ 2>/dev/null
# Server: is register_argc_argv on, and is pearcmd.php present?
php -i | grep register_argc_argv
find / -name pearcmd.php 2>/dev/null
Even if both checks come back clean, update. File inclusion bugs often find new gadgets after disclosure.
Sites with automatic background updates (on by default for minor releases) should already have received the fix for their branch. Confirm. Don’t assume.
wp core update
wp core version
| Branch | Fixed | Branch | Fixed |
|---|---|---|---|
| 7.1 | 7.1.2 | 6.4 | 6.4.12 |
| 7.0 | 7.0.6 | 6.3 | 6.3.12 |
| 6.9 | 6.9.9 | 6.2 | 6.2.13 |
| 6.8 | 6.8.10 | 6.1 | 6.1.14 |
| 6.7 | 6.7.9 | 6.0 | 6.0.16 |
| 6.6 | 6.6.9 | 5.x / 4.7–4.9 | see advisory (back to 4.7.37) |
| 6.5 | 6.5.12 |
register_argc_argv = Off in php.ini (or your PHP-FPM pool) and restart PHP.pearcmd.php unreadable by the web server user.pagename= values containing ../ or encoded variants (%2e%2e), and for requests mentioning pearcmd.wp-content/uploads/, /tmp, or theme folders: find wp-content -name '*.php' -newer wp-config.php.wp user list --role=administrator.wp core verify-checksums.Desert Forge IT patches, monitors, and backs up servers and networks for Phoenix-area businesses. We track advisories like this one so you don’t have to. Get a free consult and we’ll tell you what you’re exposed to.