Wordpress Alert: Page-template local file inclusion (CVE-2026-87902)

An affected version and the advisory's theme and server preconditions allow an unexpected local PHP file to be included. Under those conditions, unauthenticated code execution may follow.

What it looks like

An affected version and the advisory's theme and server preconditions allow an unexpected local PHP file to be included.

Why it matters

Under those conditions, unauthenticated code execution may follow.

What to check

Check the September 2026 release and update the affected core branch.

Documentation

This is a documented WordPress core vulnerability. The linked release gives the affected versions and fixes. See WordPress 7.1.2 security release.