WordPress Core contains a remote file inclusion vulnerability which could allow an unauthenticated attacker to make page-template resolution include a chosen readable local `.php` file outside the active theme directories, leading to remote code execution.
WordPress Core contains a path traversal flaw in its page-template resolution function that allows an unauthenticated attacker to force the server to include an arbitrary readable PHP file from outside the active theme directories. Affected installations span all WordPress releases below 7.1.2 (and below the corresponding backport boundaries for older release lines). Active exploitation was observed within hours of the patch release, with attackers progressing from reconnaissance to file-write payloads within a day.
The vulnerability (CWE-98) sits in WordPress's get_page_template() function, which resolves which PHP file to load for a given page. The function fails to sanitize the pagename query parameter before passing it to PHP's file inclusion mechanism. An attacker can inject path traversal sequences into that parameter, causing the inclusion to resolve to any readable PHP file on the server rather than a file within the active theme. This is a classic improper control of a filename for an include statement: user-supplied input crosses a trust boundary and directly controls which file PHP executes.
An unauthenticated attacker sends a crafted HTTP GET request with a manipulated pagename parameter containing traversal sequences, along with a valid or guessable page_id. At minimum, the server's response to an included benign core file confirms whether the host is vulnerable. When PEAR is installed and PHP is configured with register_argc_argv enabled, the attacker can target pearcmd.php and pass additional query-string arguments that pearcmd interprets as commands, using config-create to write attacker-controlled PHP content to disk. This constitutes arbitrary file write and remote code execution. Full exploitation requires the PEAR and register_argc_argv preconditions, plus unspecified active-theme and server conditions noted in the vendor advisory.
This vulnerability is confirmed as actively exploited in the wild — it is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.
pagename values with URL-encoded path traversal sequences (e.g., %2f or %2e%2e) combined with page_id parameters, particularly targeting known core PHP files such as wp-links-opml.php, wp-login.php, or pearcmd.php paths./tmp and /var/tmp, especially files with names matching observed patterns (poc87902.php, luci_*.php, zeta_*.php, wp-pear-rce-flag.php) that have no corresponding deployment event.cve-2026-87902-poc/1.0 or nuclei-cve-2026-87902/1.0; treat any match as confirmed exploitation attempt regardless of payload stage.register_argc_argv in php.ini if it is not required by the application; this removes the query-string-to-argv exposure that pearcmd exploitation depends on, blocking the file-write RCE path even on unpatched hosts.pearcmd.php and other PEAR installation files if PEAR is not actively used; their absence eliminates the primary observed code-execution primitive without requiring a PHP configuration change.pagename contains URL-encoded slash or dot-dot sequences (%2f, %2e%2e) combined with page_id; this matches the exact encoding the patch addresses and is the pattern Patchstack's RapidMitigate rule targets.If WordPress Core runs inside your authorization boundary, CVE-2026-87902 is a direct concern for your Federal Risk and Authorization Management Program (FedRAMP) authorization. CISA has listed it on the Known Exploited Vulnerabilities (KEV) catalog with a remediation deadline of September 28, 2026. An unpatched KEV inside your boundary is an assessor finding. You must either remediate it or formally document a mitigation before your assessor and sponsoring agency raise it.
Knox does not patch WordPress Core on your behalf. Under the FedRAMP shared-responsibility model, remediating WordPress Core is your obligation. What Knox provides is the pre-authorized, single-tenant boundary to carry out that remediation in, plus Knox's automated continuous monitoring platform and audit-artifact coverage to document the fix for your next assessment. The work of applying the patch is yours. Managing your compliance posture while you do it is not something you handle alone.
Knox's automated continuous monitoring platform watches your environment for newly disclosed vulnerabilities and compliance issues on a continuous basis. When something like CVE-2026-87902 surfaces, exposure is identified through ongoing monitoring rather than waiting for an assessor to flag it at a scheduled review. That difference in timing gives your team room to act before a finding becomes a formal record.
Knox runs a FedRAMP-as-a-Service platform. It gives SaaS vendors a pre-authorized cloud boundary on AWS, Azure, and GCP. Your application inherits 60-80% of the required security controls. You reach FedRAMP authorization in about 90 days for roughly 90% less than the traditional $3.5M path. Book a meeting and Knox will map your path to authorization.
An unremediated CVE-2026-87902 becomes a Plan of Action and Milestones (POA&M) item. A growing POA&M list is precisely what turns a routine continuous-monitoring review into a difficult conversation with your sponsoring agency. Closing out the finding and documenting the remediation keeps your authorization clean and preserves the agency relationship that underpins your federal business.
Schedule a meeting to discuss scope, parse readiness, and map your company’s accelerated path to FedRAMP authorization.









_Horizontal_RGB.png)








