{"id":"BIT-wordpress-2026-87902","details":"An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the active theme directories. If relevant pre-conditions for both the server and the active theme are met, this can lead to RCE.","aliases":["BIT-wordpress-multisite-2026-87902","CVE-2026-87902"],"modified":"2026-09-29T10:11:04.780640711Z","published":"2026-09-29T09:00:28.803Z","database_specific":{"severity":"High","cpes":["cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:*"]},"references":[{"type":"ADVISORY","url":"https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-7hp8-65ch-5whp"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-87902"},{"type":"ADVISORY","url":"https://patchstack.com/articles/cve-2026-87902-attackers-started-probing-wordpress-sites-hours-after-the-patch/"},{"type":"WEB","url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-87902"}],"affected":[{"package":{"name":"wordpress","ecosystem":"Bitnami","purl":"pkg:bitnami/wordpress"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"4.7.37"},{"introduced":"4.8.0"},{"fixed":"4.8.32"},{"introduced":"4.9.0"},{"fixed":"4.9.33"},{"introduced":"5.0.0"},{"fixed":"5.0.29"},{"introduced":"5.1.0"},{"fixed":"5.1.26"},{"introduced":"5.2.0"},{"fixed":"5.2.28"},{"introduced":"5.3.0"},{"fixed":"5.3.25"},{"introduced":"5.4.0"},{"fixed":"5.4.23"},{"introduced":"5.5.0"},{"fixed":"5.5.22"},{"introduced":"5.6.0"},{"fixed":"5.6.21"},{"introduced":"5.7.0"},{"fixed":"5.7.19"},{"introduced":"5.8.0"},{"fixed":"5.8.17"},{"introduced":"5.9.0"},{"fixed":"5.9.18"},{"introduced":"6.0.0"},{"fixed":"6.0.16"},{"introduced":"6.1.0"},{"fixed":"6.1.14"},{"introduced":"6.2.0"},{"fixed":"6.2.13"},{"introduced":"6.3.0"},{"fixed":"6.3.12"},{"introduced":"6.4.0"},{"fixed":"6.4.12"},{"introduced":"6.5.0"},{"fixed":"6.5.12"},{"introduced":"6.6.0"},{"fixed":"6.6.9"},{"introduced":"6.7.0"},{"fixed":"6.7.9"},{"introduced":"6.8.0"},{"fixed":"6.8.10"},{"introduced":"6.9.0"},{"fixed":"6.9.9"},{"introduced":"7.0.0"},{"fixed":"7.0.6"},{"introduced":"7.1.0"},{"fixed":"7.1.2"}]}],"database_specific":{"source":"https://github.com/bitnami/vulndb/tree/main/data/wordpress/BIT-wordpress-2026-87902.json"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}],"schema_version":"1.9.0"}