CVE-2026-87902
wordpress-multisite: Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') (CVE-2026-87902)
Response & Mitigation
Why act now?
Prioritisation rationale
CVE-2026-87902 carries a CVSS 8.1 score (AV:N/AC:H/PR:N/UI:N) and sits at the 86th EPSS percentile, meaning the statistical exploitation probability exceeds that of more than 86 % of all tracked CVEs. The High attack complexity (AC:H) reflects specific server and theme pre-conditions, but these conditions are commonly met in default WordPress deployments, so the effective risk for most organisations is not materially lower than the base score suggests. For NIS2-regulated entities — particularly those running WordPress as a public-facing CMS for essential or important services — a successful exploit yields full server compromise and a viable pivot point into internal networks. The CISA KEV flag without a known ransomware campaign association slightly reduces the immediate escalation pressure compared to ransomware-linked CVEs, but does not change the patching obligation: affected instances should be remediated within 72 hours in line with standard critical-web-application patch timelines.
Runbook · Step 1
Immediate response (0-24 h)
- Apply the vendor patch immediately: Update WordPress to the patched release matching your active branch — 6.4.12, 6.5.12, 6.6.9, 6.7.9, 6.8.10, 6.9.9, 7.0.6, or 7.1.2. Use the WordPress admin dashboard (Dashboard → Updates) or WP-CLI:
wp core update --version=<target-version>. - Enable automatic core updates: If not already set, add
define('WP_AUTO_UPDATE_CORE', true);towp-config.phpto ensure future security releases are applied without manual intervention. - Inventory all exposed WordPress instances: Enumerate every internet-facing WordPress installation including subdomains and staging environments. Unpatched instances must be taken offline or placed behind a WAF immediately.
- Enforce PHP include restrictions: Confirm
allow_url_include = Offandallow_url_fopen = Offinphp.inion all hosting servers — this limits the remote-file-inclusion attack surface at the PHP runtime level. - Review web server logs for exploitation attempts: Immediately search access logs for query parameters such as
page_template=ortemplate=combined with path-traversal sequences (../,%2e%2e) or absolute paths in GET/POST requests.
Runbook · Step 2
Mitigation layers
- WAF rule (network layer): Block or alert on requests containing path-traversal sequences (
../,%2e%2e%2f,....//) or absolute filesystem paths (/etc/,/var/www/) in query parameters targeting WordPress endpoints. ModSecurity example:SecRule ARGS "@rx (?:\.\.[\\/]|%2e%2e[\\/]|\/etc\/|\/var\/)" "id:9001,phase:2,deny,log,msg:'CVE-2026-87902 LFI attempt'". - PHP open_basedir restriction: Set
open_basedirto the WordPress document root and required system paths only — this prevents file includes outside the permitted directory tree at the OS level, regardless of application logic. - Least-privilege web server process: Run PHP-FPM or Apache under a dedicated, unprivileged system account. Set filesystem permissions so that only theme directories and
wp-contentare readable by the web process. - Network segmentation: Place WordPress servers in a DMZ or dedicated VLAN. Restrict outbound connections from the web server to required destinations only (update servers, CDN) — this limits post-exploitation callback and lateral movement options.
- Take staging and development instances offline: These are typically less hardened and often run the same themes as production. Bind them to
127.0.0.1or remove them from DNS until patched. - File-integrity monitoring on theme directories: Configure FIM (e.g. Wazuh, AIDE) on
wp-content/themes/andwp-includes/to alert on newly created or modified.phpfiles — a key indicator of successful exploitation.
Runbook · Step 3
Detection rules
- Web server access logs (Apache/Nginx): Search for query strings combining template-related parameters with traversal or absolute paths:
grep -E "(page_template|template)=(\.\.|%2e|/etc|/var|/tmp)" /var/log/nginx/access.log - Linux auditd: Alert on
opensyscalls against.phpfiles outside/var/www/<webroot>/wp-content/themes/by the web server process UID:auditctl -a always,exit -F arch=b64 -S open -F uid=<www-data-uid> -F path!=/var/www/ -k cve_2026_87902 - Sysmon (Windows hosting): Event ID 1 (ProcessCreate) where ParentImage matches
*php*and Image matches*cmd*,*powershell*, or*sh*— Sigma shape:EventID: 1 | ParentImage: '*php*' | Image: '*cmd*|*powershell*|*sh*' - EDR process-ancestry chain: Web server process (
apache2,nginx,php-fpm) spawning shell processes (/bin/sh,/bin/bash) or network utilities (curl,wget,nc) is a high-confidence indicator of successful RCE. - SIEM correlation (KQL/SPL): Cluster of HTTP 200/403/500 responses to the same WordPress URL with varying
templateparameter values within a short window indicates automated scanning or exploitation:index=webserver status IN (200,403,500) uri_query="*template*" | stats count by src_ip, uri_path | where count > 20
Description
An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the active theme directories. If relevant pre-conditions for both the server and the active theme are met, this can lead to RCE.
Affected products
The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.
Metrics
Show all metrics
Weakness classes (CWE)
CWE-98Variant
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
The PHP application receives input from an upstream component, but it does not restrict or incorrectly restricts the input before its usage in "require," "include," or similar functions.
cwe.mitre.org →
Public exploit references
Public proof-of-concepts and detection templates for this vulnerability. Maturity ranges from reported PoCs through working detection scripts up to fully weaponized exploit modules. NEOSEC mirrors the code internally for forensic analysis; externally we only link to the original sources.
References & sources
- https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-7hp8-65ch-5whp
- https://patchstack.com/articles/cve-2026-87902-attackers-started-probing-wordpress-sites-hours-after-the-patch/third-party-advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-87902government-resource
- https://nvd.nist.gov/vuln/detail/CVE-2026-87902web
Reanalysis & status changes
Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.
- Initial Analysis2026-09-28 12:20 UTC· nvd@nist.gov
- CPE Configuration: OR *cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:* versions from (including) 4.8 up to (excluding) 4.8.32 *cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:* versions from (including) 4.9 up to (excluding) 4.9.33 *cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:* versions from (including) 5.0 up to (excluding) 5.0.29 *cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:* versions from (including) 5.1 up to (excluding) 5.1.26 *cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:* versions from (including) 5.2 up to (excluding) 5.2.28 *cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:* versions from (including) 5.3 up to (excluding) 5.3.25 *cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:* versions from (including) 5.4 up to (excluding) 5.4.23 *cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:* versions from (including) 5.5 up to (excluding) 5.5.22 *cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:* versions from (including) 5.6 up to (excluding) 5.6.21 *cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:* versions from (including) 5.7 up to (excluding) 5.7.19 *cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:* versions from (including) 5.8 up to (excluding) 5.8.17 *cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:* versions from (including) 5.9 up to (excluding) 5.9.18 *cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:* versions from (including) 6.0 up to (excluding) 6.0.16 *cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:* versions from (including) 6.1 up to (excluding) 6.1.14 *cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:* versions from (including) 6.2 up to (excluding) 6.2.13 *cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:* versions from (including) 6.3 up to (excluding) 6.3.12 *cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:* versions from (including) 6.4 up to (excluding) 6.4.12 *cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:* versions from (including) 6.5 up to (excluding) 6.5.12 *cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:* versions from (including) 6.6 up to (excluding) 6.6.9 *cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:* versions from (including) 6.7 up to (excluding) 6.7.9 *cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:* versions from (including) 6.8 up to (excluding) 6.8.10 *cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:* versions from (including) 6.9 up to (excluding) 6.9.9 *cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:* versions from (including) 7.0 up to (excluding) 7.0.6 *cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:* versions up to (excluding) 4.7.37 *cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:* versions from (including) 7.1 up to (excluding) 7.1.2
- Reference Type: HackerOne: https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-7hp8-65ch-5whp Types: Vendor Advisory
- Reference Type: CISA-ADP: https://patchstack.com/articles/cve-2026-87902-attackers-started-probing-wordpress-sites-hours-after-the-patch/ Types: Third Party Advisory
- Reference Type: CISA-ADP: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-87902 Types: US Government Resource
- CVE Modified2026-09-26 04:17 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
- SSVC: {"id":"CVE-2026-87902","role":"CISA Coordinator","options":[{"exploitation":"active"},{"automatable":"no"},{"technica…
- SSVC: {"id":"CVE-2026-87902","role":"CISA Coordinator","options":[{"exploitation":"active"},{"automatable":"no"},{"technica…
- CVE CISA KEV Update2026-09-25 22:00 UTC· 9119a7d8-5eab-497f-8521-727c672e3725
- Date Added: 2026-09-25
- Due Date: 2026-09-25
- Required Action: 2026-09-25
- Vulnerability Name: 2026-09-25
- CVE Modified2026-09-25 20:17 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
- Reference: https://patchstack.com/articles/cve-2026-87902-attackers-started-probing-wordpress-sites-hours-after-the-patch/
- Reference: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-87902
- SSVC: {"id":"CVE-2026-87902","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalI…
- SSVC: {"id":"CVE-2026-87902","role":"CISA Coordinator","options":[{"exploitation":"active"},{"automatable":"no"},{"technica…
- New CVE Received2026-09-22 17:17 UTC· support@hackerone.com
- Description: An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the active theme directories. If relevant pre-conditions for both the server and the active theme are met, this can lead to RCE.
- CWE: CWE-98
- Affected: New affected value received. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/87xxx/CVE-2026-87902.json">CVE-2026-87902</a>
- Reference: https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-7hp8-65ch-5whp
Linked advisories
- csoonline2026-09-24 20:26 UTCWordPress patches a critical severity security vulnerability
- ncsc-nl2026-09-24 09:14 UTCNCSC-2026-0389 [1.01] [M/H] Kwetsbaarheid verholpen in WordPress
- securityweek2026-09-24 07:12 UTCCritical WordPress Vulnerability Exploited Immediately After Disclosure
- thehackernews2026-09-24 05:36 UTCAttackers Exploit WordPress CVE-2026-87902 Within Hours of Disclosure
- bleepingcomputer2026-09-23 18:31 UTCHackers start exploiting critical WordPress flaw for code execution
- ncsc-nl2026-09-23 11:47 UTCNCSC-2026-0389 [1.00] [M/H] Kwetsbaarheid verholpen in WordPress