• Sources: primary, discussion
  • Summary: The advisory covers CVE-2026-87902, CVSS v4 base score 9.2, published 2026-09-22, where an unauthenticated attacker can make get_page_template() resolution include a chosen readable local .php file outside the active theme directories. Reaching code execution requires two preconditions: the active child or parent theme contains a top-level directory whose name starts with page-, which covers Twenty Twelve, Twenty Fourteen, Neve, Hestia, and Sydney, and a chosen readable local .php target exists, for which the advisory names the PEAR pearcmd.php path with register_argc_argv set to On. The advisory states the official php Docker image is affected and the default cPanel configuration is affected on PHP before 8.5, and the fix ships in 7.1.2 with backports across 25 branches to 4.7.37.
  • Why it matters: Attack vector is network with no privileges and no user interaction, and the backport reach to 4.7.37 means the upgrade applies to nearly every install still receiving WordPress security releases.

send feedback on this story