Skip to content
Critical Local File Inclusion Vulnerability in WordPress Core

Critical Local File Inclusion Vulnerability in WordPress Core

First seen 22 Sep 2026, 21:25 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 22, 2026 at 21:59 UTC
  • CVE-2026-87902 allows unauthenticated local file inclusion in WordPress Core.
  • All versions up to 7.1.1 are affected; patch available in version 7.1.2.
  • Exploitation can lead to remote code execution under specific conditions.

A critical vulnerability (CVE-2026-87902) has been discovered in WordPress Core, affecting all versions up to 7.1.1. This flaw allows unauthenticated local file inclusion via the locate_template() function, potentially leading to remote code execution under specific conditions. The vulnerability arises from improper handling of the `pagename` parameter, which can be exploited to include arbitrary PHP files. WordPress has released a patch (version 7.1.2) to address this issue, and users are urged to update immediately. Proof-of-concept code has been verified, and the vulnerability has a CVSS score of 9.2, indicating critical severity. Attackers can exploit this flaw without authentication, making it particularly dangerous for WordPress installations. The vulnerability was disclosed on September 22, 2026, and is confirmed to be exploitable in the wild.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-22
CVE-2026-87902 published
WordPress disclosed a critical local file inclusion vulnerability affecting versions up to 7.1.1.
Sploitus
2026-09-22
Patch released for WordPress
WordPress released version 7.1.2 to fix the local file inclusion vulnerability.
Sploitus

More articles in this cluster (2)

Following this threat?

Track Pear and CVE-2026-87902 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed