Wordpress Alert: Page-template local file inclusion (CVE-2026-87902)
An affected version and the advisory's theme and server preconditions allow an unexpected local PHP file to be included. Under those conditions, unauthenticated code execution may follow.
What it looks like
An affected version and the advisory's theme and server preconditions allow an unexpected local PHP file to be included.
Why it matters
Under those conditions, unauthenticated code execution may follow.
What to check
Check the September 2026 release and update the affected core branch.
Documentation
This is a documented WordPress core vulnerability. The linked release gives the affected versions and fixes. See WordPress 7.1.2 security release.
- Categories: WordPress
- Tags: #WordPress Security, #Core Security, #Security Advisories