WordPress Issues Patch for Critical Flaw That Can Enable Code Execution on Some Servers
Read original article ↗AI Summary
WordPress has patched a critical vulnerability, CVE-2026-87902, that allows unauthenticated attackers to exploit a path traversal flaw in the template loading mechanism, potentially leading to remote code execution on vulnerable servers. The vulnerability affects all WordPress versions from 4.7.0 to 7.1.1 and stems from insufficient sanitization of user-supplied input used to construct template file paths. Successful exploitation requires the active theme to have a top-level directory starting with 'page-' and depends on server-side PHP configuration (e.g., register_argc_argv enabled) for full code execution. While no active exploitation has been observed as of September 22, 2026, the flaw is rated with a CVSS score of 9.2 and affects a wide range of WordPress installations.
AI-extracted · verify before operational use
No entities or IoCs were extracted from this article.