Knox CVE Database
/
CVE-2026-87902
High
8.1

CVE-2026-87902: WordPress Core Remote File Inclusion Vulnerability

WordPress Core contains a remote file inclusion vulnerability which could allow an unauthenticated attacker to make page-template resolution include a chosen readable local `.php` file outside the active theme directories, leading to remote code execution.

Added to the CISA KEV catalog:
September 25, 2026

Overview

WordPress Core contains a path traversal flaw in its page-template resolution function that allows an unauthenticated attacker to force the server to include an arbitrary readable PHP file from outside the active theme directories. Affected installations span all WordPress releases below 7.1.2 (and below the corresponding backport boundaries for older release lines). Active exploitation was observed within hours of the patch release, with attackers progressing from reconnaissance to file-write payloads within a day.

Vulnerability details

Affected vendor
WordPress
Affected product
Core
Weakness type (CWE)
CWE-98

The vulnerability (CWE-98) sits in WordPress's get_page_template() function, which resolves which PHP file to load for a given page. The function fails to sanitize the pagename query parameter before passing it to PHP's file inclusion mechanism. An attacker can inject path traversal sequences into that parameter, causing the inclusion to resolve to any readable PHP file on the server rather than a file within the active theme. This is a classic improper control of a filename for an include statement: user-supplied input crosses a trust boundary and directly controls which file PHP executes.


An unauthenticated attacker sends a crafted HTTP GET request with a manipulated pagename parameter containing traversal sequences, along with a valid or guessable page_id. At minimum, the server's response to an included benign core file confirms whether the host is vulnerable. When PEAR is installed and PHP is configured with register_argc_argv enabled, the attacker can target pearcmd.php and pass additional query-string arguments that pearcmd interprets as commands, using config-create to write attacker-controlled PHP content to disk. This constitutes arbitrary file write and remote code execution. Full exploitation requires the PEAR and register_argc_argv preconditions, plus unspecified active-theme and server conditions noted in the vendor advisory.

Severity and impact

8.1
High
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack vector
Network
Attack complexity
High
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality impact
High
Integrity impact
High
Availability impact
High

Exploitation status

This vulnerability is confirmed as actively exploited in the wild — it is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.

Known ransomware campaign use
Unknown

Detection and monitoring

  • Review web server access logs for GET requests containing pagename values with URL-encoded path traversal sequences (e.g., %2f or %2e%2e) combined with page_id parameters, particularly targeting known core PHP files such as wp-links-opml.php, wp-login.php, or pearcmd.php paths.
  • Monitor for unexpected PHP file creation in world-writable directories such as /tmp and /var/tmp, especially files with names matching observed patterns (poc87902.php, luci_*.php, zeta_*.php, wp-pear-rce-flag.php) that have no corresponding deployment event.
  • Inspect access logs for requests bearing user agents cve-2026-87902-poc/1.0 or nuclei-cve-2026-87902/1.0; treat any match as confirmed exploitation attempt regardless of payload stage.

Remediation

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see References) guidance and CISA’s “Forensics Triage Requirements” (see References). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Federal (FCEB) remediation due date
September 28, 2026

Additional hardening

  • Update WordPress to 7.1.2 or, for older release lines, to 4.7.37, 4.8.32, 4.9.33, 5.0.29, 5.1.26, 5.2.28, or 5.3.25 as applicable; see the vendor advisory in References for the full boundary list.
  • Disable register_argc_argv in php.ini if it is not required by the application; this removes the query-string-to-argv exposure that pearcmd exploitation depends on, blocking the file-write RCE path even on unpatched hosts.
  • Remove or restrict access to pearcmd.php and other PEAR installation files if PEAR is not actively used; their absence eliminates the primary observed code-execution primitive without requiring a PHP configuration change.
  • Place a web application firewall rule blocking requests where pagename contains URL-encoded slash or dot-dot sequences (%2f, %2e%2e) combined with page_id; this matches the exact encoding the patch addresses and is the pattern Patchstack's RapidMitigate rule targets.

Key dates

Published (NVD)
September 22, 2026
Added to CISA KEV
September 25, 2026
Remediation deadline
September 28, 2026
Last updated
September 28, 2026

References

Frequently asked questions

Does CVE-2026-87902 affect my FedRAMP authorization?

If WordPress Core runs inside your authorization boundary, CVE-2026-87902 is a direct concern for your Federal Risk and Authorization Management Program (FedRAMP) authorization. CISA has listed it on the Known Exploited Vulnerabilities (KEV) catalog with a remediation deadline of September 28, 2026. An unpatched KEV inside your boundary is an assessor finding. You must either remediate it or formally document a mitigation before your assessor and sponsoring agency raise it.

How does Knox help me handle CVE-2026-87902?

Knox does not patch WordPress Core on your behalf. Under the FedRAMP shared-responsibility model, remediating WordPress Core is your obligation. What Knox provides is the pre-authorized, single-tenant boundary to carry out that remediation in, plus Knox's automated continuous monitoring platform and audit-artifact coverage to document the fix for your next assessment. The work of applying the patch is yours. Managing your compliance posture while you do it is not something you handle alone.

How does Knox's monitoring help with vulnerabilities like this?

Knox's automated continuous monitoring platform watches your environment for newly disclosed vulnerabilities and compliance issues on a continuous basis. When something like CVE-2026-87902 surfaces, exposure is identified through ongoing monitoring rather than waiting for an assessor to flag it at a scheduled review. That difference in timing gives your team room to act before a finding becomes a formal record.

How do I get FedRAMP authorized with Knox?

Knox runs a FedRAMP-as-a-Service platform. It gives SaaS vendors a pre-authorized cloud boundary on AWS, Azure, and GCP. Your application inherits 60-80% of the required security controls. You reach FedRAMP authorization in about 90 days for roughly 90% less than the traditional $3.5M path. Book a meeting and Knox will map your path to authorization.

What happens if CVE-2026-87902 isn't remediated by September 28, 2026?

An unremediated CVE-2026-87902 becomes a Plan of Action and Milestones (POA&M) item. A growing POA&M list is precisely what turns a routine continuous-monitoring review into a difficult conversation with your sponsoring agency. Closing out the finding and documenting the remediation keeps your authorization clean and preserves the agency relationship that underpins your federal business.

Ready to achieve FedRAMP authorization in 90 days or less?

Schedule a meeting to discuss scope, parse readiness, and map your company’s accelerated path to FedRAMP authorization.