High · 7.8 WordPress NCSC-2026-0389 CVE-2026-87902 Actively exploited
WordPress Core Local File Inclusion Flaw Allows Remote Code Execution (CVE-2026-87902)
A vulnerability in WordPress Core's get_page_template() function allows an unauthenticated attacker to include an arbitrary readable local PHP file outside the active theme directory, which can lead to remote code execution under certain server and theme conditions. Patches are available across all supported WordPress release branches.
AI summary
A vulnerability has been identified in WordPress Core affecting the page-template resolution logic used by the get_page_template() function. The issue allows an unauthenticated attacker to cause the function to include a local .php file of their choosing from outside the active theme's directories, provided that file is readable on the server. Under certain additional conditions related to server configuration and the active theme, this file inclusion can be leveraged to achieve remote code execution. The vendor has released fixed versions across all currently maintained WordPress release branches.
What happened
WordPress Core's get_page_template() function, which resolves which template file to load for a given page, can be manipulated by an unauthenticated attacker to include a local .php file located outside the directories belonging to the active theme. This is a local file inclusion issue (CWE-98) in the page-template resolution path.
Technical cause
The root cause is improper validation of the file path used by get_page_template() when resolving page templates. Because the function does not sufficiently restrict which files can be loaded, an attacker can direct it to include any readable local .php file rather than only files within the intended theme directories.
Why it matters
If the attacker can get a suitable PHP file onto the server (for example through an unrelated upload mechanism, a log file, or another means) and the active theme and server configuration meet certain additional preconditions, the inclusion of that file can result in remote code execution. The vulnerability requires no authentication and no user interaction, which increases its potential impact on affected sites.
Who is affected
All WordPress Core installations across the listed release branches, from version 4.7 through 7.1, are affected unless updated to the fixed version for their branch. Given WordPress Core's extremely wide deployment base, a large number of sites could potentially be affected.
Discovery and timeline
CVE-2026-87902 was published on 2026-09-22 and the corresponding NCSC-NL advisory (NCSC-2026-0389) was issued on 2026-09-24. The fact package indicates this vulnerability is known to be exploited; however, no further details on discovery or exploitation circumstances were provided in the available source material, and no public exploit code has been confirmed.
Affected versions
The vulnerability affects WordPress Core versions starting from 0 up to but not including the fixed version in each branch: versions before 4.7.37, 4.8 before 4.8.32, 4.9 before 4.9.33, 5.0 before 5.0.29, 5.1 before 5.1.26, 5.2 before 5.2.28, 5.3 before 5.3.25, 5.4 before 5.4.23, 5.5 before 5.5.22, 5.6 before 5.6.21, 5.7 before 5.7.19, 5.8 before 5.8.17, 5.9 before 5.9.18, 6.0 before 6.0.16, 6.1 before 6.1.14, 6.2 before 6.2.13, 6.3 before 6.3.12, 6.4 before 6.4.12, 6.5 before 6.5.12, 6.6 before 6.6.9, 6.7 before 6.7.9, 6.8 before 6.8.10, 6.9 before 6.9.9, 7.0 before 7.0.6, and 7.1 before 7.1.2.
Fixes and mitigation
Fixed versions are available for every affected branch: 4.7.37, 4.8.32, 4.9.33, 5.0.29, 5.1.26, 5.2.28, 5.3.25, 5.4.23, 5.5.22, 5.6.21, 5.7.19, 5.8.17, 5.9.18, 6.0.16, 6.1.14, 6.2.13, 6.3.12, 6.4.12, 6.5.12, 6.6.9, 6.7.9, 6.8.10, 6.9.9, 7.0.6, and 7.1.2. Site administrators should update to the fixed version corresponding to their current branch.
Recommended action
Update WordPress Core to the fixed version applicable to your installed branch as soon as possible. Because this vulnerability is listed as known exploited, treat patching as urgent rather than routine maintenance. Review server configuration and theme code where feasible to reduce exposure to local file inclusion issues in general.
PatchBriefing score
7.8 / 10 · High
Official CVSS: 8.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Listed in CISA KEV since September 25, 2026
Why this score
This advisory carries a PatchBriefing score of 7.8, driven primarily by a CVSS base score of 8.1 (AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H), reflecting a network-exploitable issue with high confidentiality, integrity, and availability impact, requiring no privileges or user interaction. The score is further increased because the vulnerability is known to be exploited, and because it can be triggered without authentication or user interaction. The extremely large deployment base of WordPress Core contributes a modest additional factor. No public exploit code or EPSS data was available in the fact package. NCSC-NL rates the damage potential as High and the likelihood ('chance') as Medium.
Affected versions
- WordPress Core ≥ 0 < 4.7.37
- vulnerable
- WordPress Core ≥ 4.8 < 4.8.32
- vulnerable
- WordPress Core ≥ 4.9 < 4.9.33
- vulnerable
- WordPress Core ≥ 5.0 < 5.0.29
- vulnerable
- WordPress Core ≥ 5.1 < 5.1.26
- vulnerable
- WordPress Core ≥ 5.2 < 5.2.28
- vulnerable
- WordPress Core ≥ 5.3 < 5.3.25
- vulnerable
- WordPress Core ≥ 5.4 < 5.4.23
- vulnerable
- WordPress Core ≥ 5.5 < 5.5.22
- vulnerable
- WordPress Core ≥ 5.6 < 5.6.21
- vulnerable
- WordPress Core ≥ 5.7 < 5.7.19
- vulnerable
- WordPress Core ≥ 5.8 < 5.8.17
- vulnerable
- WordPress Core ≥ 5.9 < 5.9.18
- vulnerable
- WordPress Core ≥ 6.0 < 6.0.16
- vulnerable
- WordPress Core ≥ 6.1 < 6.1.14
- vulnerable
- WordPress Core ≥ 6.2 < 6.2.13
- vulnerable
- WordPress Core ≥ 6.3 < 6.3.12
- vulnerable
- WordPress Core ≥ 6.4 < 6.4.12
- vulnerable
- WordPress Core ≥ 6.5 < 6.5.12
- vulnerable
- WordPress Core ≥ 6.6 < 6.6.9
- vulnerable
- WordPress Core ≥ 6.7 < 6.7.9
- vulnerable
- WordPress Core ≥ 6.8 < 6.8.10
- vulnerable
- WordPress Core ≥ 6.9 < 6.9.9
- vulnerable
- WordPress Core ≥ 7.0 < 7.0.6
- vulnerable
- WordPress Core ≥ 7.1 < 7.1.2
- vulnerable
- ≥ 4.7.37
- patched
- ≥ 4.8.32
- patched
- ≥ 4.9.33
- patched
- ≥ 5.0.29
- patched
- ≥ 5.1.26
- patched
- ≥ 5.2.28
- patched
- ≥ 5.3.25
- patched
- ≥ 5.4.23
- patched
- ≥ 5.5.22
- patched
- ≥ 5.6.21
- patched
- ≥ 5.7.19
- patched
- ≥ 5.8.17
- patched
- ≥ 5.9.18
- patched
- ≥ 6.0.16
- patched
- ≥ 6.1.14
- patched
- ≥ 6.2.13
- patched
- ≥ 6.3.12
- patched
- ≥ 6.4.12
- patched
- ≥ 6.5.12
- patched
- ≥ 6.6.9
- patched
- ≥ 6.7.9
- patched
- ≥ 6.8.10
- patched
- ≥ 6.9.9
- patched
- ≥ 7.0.6
- patched
- ≥ 7.1.2
- patched
Reported fixes
Fixed versions are available for every affected branch: 4.7.37, 4.8.32, 4.9.33, 5.0.29, 5.1.26, 5.2.28, 5.3.25, 5.4.23, 5.5.22, 5.6.21, 5.7.19, 5.8.17, 5.9.18, 6.0.16, 6.1.14, 6.2.13, 6.3.12, 6.4.12, 6.5.12, 6.6.9, 6.7.9, 6.8.10, 6.9.9, 7.0.6, and 7.1.2. Site administrators should update to the fixed version corresponding to their current branch.
How this was built
2 source records were collected, matched and used to prepare the report above.
-
NCSC-NL advisories cert
-
NVD (NIST) database
Revision history
- Published
- Generated
Related
Relevant changes for the stacks you follow.
Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.
✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email