Sploitus Critical Local File Inclusion Vulnerability in WordPress Core
Article Content
- •CVE-2026-87902 allows unauthenticated local file inclusion in WordPress Core.
- •All versions up to 7.1.1 are affected; patch available in version 7.1.2.
- •Exploitation can lead to remote code execution under specific conditions.
A critical vulnerability (CVE-2026-87902) has been discovered in WordPress Core, affecting all versions up to 7.1.1. This flaw allows unauthenticated local file inclusion via the locate_template() function, potentially leading to remote code execution under specific conditions. The vulnerability arises from improper handling of the `pagename` parameter, which can be exploited to include arbitrary PHP files. WordPress has released a patch (version 7.1.2) to address this issue, and users are urged to update immediately. Proof-of-concept code has been verified, and the vulnerability has a CVSS score of 9.2, indicating critical severity. Attackers can exploit this flaw without authentication, making it particularly dangerous for WordPress installations. The vulnerability was disclosed on September 22, 2026, and is confirmed to be exploitable in the wild.
Ask AI about this cluster
Answers cite the sources they use
More articles in this cluster (2)
Following this threat?
Track Pear and CVE-2026-87902 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Wallstreet Hacking Group Claims Cyberattack on Cedar County Memorial Hospital In August 2026, Cedar County Memorial Hospital in Missouri suffered a cyberattack that disrupted its IT systems, leading to the hospital's patient portal and electronic health record (EHR) system being taken offline. The hospital confirmed the attack on August 23, 2026, and implemented measures to secure its systems…
Critical WordPress Flaw Allows Remote Code Execution WordPress has released version 7.1.2 to address a critical vulnerability (CVE-2026-87902) that allows unauthenticated attackers to execute code on certain servers by loading a PHP file from outside the theme directories. The flaw affects all versions from 4.7.0 to 7.1.1, and site owners are urged to update…