CVE-2026-87902

wordpress-multisite: Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') (CVE-2026-87902)

Response & Mitigation

Why act now?

Prioritisation rationale

CVE-2026-87902 carries a CVSS 8.1 score (AV:N/AC:H/PR:N/UI:N) and sits at the 86th EPSS percentile, meaning the statistical exploitation probability exceeds that of more than 86 % of all tracked CVEs. The High attack complexity (AC:H) reflects specific server and theme pre-conditions, but these conditions are commonly met in default WordPress deployments, so the effective risk for most organisations is not materially lower than the base score suggests. For NIS2-regulated entities — particularly those running WordPress as a public-facing CMS for essential or important services — a successful exploit yields full server compromise and a viable pivot point into internal networks. The CISA KEV flag without a known ransomware campaign association slightly reduces the immediate escalation pressure compared to ransomware-linked CVEs, but does not change the patching obligation: affected instances should be remediated within 72 hours in line with standard critical-web-application patch timelines.

Runbook · Step 1

Immediate response (0-24 h)

  • Apply the vendor patch immediately: Update WordPress to the patched release matching your active branch — 6.4.12, 6.5.12, 6.6.9, 6.7.9, 6.8.10, 6.9.9, 7.0.6, or 7.1.2. Use the WordPress admin dashboard (Dashboard → Updates) or WP-CLI: wp core update --version=<target-version>.
  • Enable automatic core updates: If not already set, add define('WP_AUTO_UPDATE_CORE', true); to wp-config.php to ensure future security releases are applied without manual intervention.
  • Inventory all exposed WordPress instances: Enumerate every internet-facing WordPress installation including subdomains and staging environments. Unpatched instances must be taken offline or placed behind a WAF immediately.
  • Enforce PHP include restrictions: Confirm allow_url_include = Off and allow_url_fopen = Off in php.ini on all hosting servers — this limits the remote-file-inclusion attack surface at the PHP runtime level.
  • Review web server logs for exploitation attempts: Immediately search access logs for query parameters such as page_template= or template= combined with path-traversal sequences (../, %2e%2e) or absolute paths in GET/POST requests.

Runbook · Step 2

Mitigation layers

  • WAF rule (network layer): Block or alert on requests containing path-traversal sequences (../, %2e%2e%2f, ....//) or absolute filesystem paths (/etc/, /var/www/) in query parameters targeting WordPress endpoints. ModSecurity example: SecRule ARGS "@rx (?:\.\.[\\/]|%2e%2e[\\/]|\/etc\/|\/var\/)" "id:9001,phase:2,deny,log,msg:'CVE-2026-87902 LFI attempt'".
  • PHP open_basedir restriction: Set open_basedir to the WordPress document root and required system paths only — this prevents file includes outside the permitted directory tree at the OS level, regardless of application logic.
  • Least-privilege web server process: Run PHP-FPM or Apache under a dedicated, unprivileged system account. Set filesystem permissions so that only theme directories and wp-content are readable by the web process.
  • Network segmentation: Place WordPress servers in a DMZ or dedicated VLAN. Restrict outbound connections from the web server to required destinations only (update servers, CDN) — this limits post-exploitation callback and lateral movement options.
  • Take staging and development instances offline: These are typically less hardened and often run the same themes as production. Bind them to 127.0.0.1 or remove them from DNS until patched.
  • File-integrity monitoring on theme directories: Configure FIM (e.g. Wazuh, AIDE) on wp-content/themes/ and wp-includes/ to alert on newly created or modified .php files — a key indicator of successful exploitation.

Runbook · Step 3

Detection rules

  • Web server access logs (Apache/Nginx): Search for query strings combining template-related parameters with traversal or absolute paths: grep -E "(page_template|template)=(\.\.|%2e|/etc|/var|/tmp)" /var/log/nginx/access.log
  • Linux auditd: Alert on open syscalls against .php files outside /var/www/<webroot>/wp-content/themes/ by the web server process UID: auditctl -a always,exit -F arch=b64 -S open -F uid=<www-data-uid> -F path!=/var/www/ -k cve_2026_87902
  • Sysmon (Windows hosting): Event ID 1 (ProcessCreate) where ParentImage matches *php* and Image matches *cmd*, *powershell*, or *sh* — Sigma shape: EventID: 1 | ParentImage: '*php*' | Image: '*cmd*|*powershell*|*sh*'
  • EDR process-ancestry chain: Web server process (apache2, nginx, php-fpm) spawning shell processes (/bin/sh, /bin/bash) or network utilities (curl, wget, nc) is a high-confidence indicator of successful RCE.
  • SIEM correlation (KQL/SPL): Cluster of HTTP 200/403/500 responses to the same WordPress URL with varying template parameter values within a short window indicates automated scanning or exploitation: index=webserver status IN (200,403,500) uri_query="*template*" | stats count by src_ip, uri_path | where count > 20

Description

An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the active theme directories. If relevant pre-conditions for both the server and the active theme are met, this can lead to RCE.

Affected products

The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.

bitnamiwordpress-multisite

Metrics

8.1
Source: cna-v3
98.6 %
Critical — this CVE ranks in the top fifth of all CVEs scored today (rank ≥ 80%).
Actively exploited
Show all metrics
Severity
critical
actively exploited (KEV)
40.0 %
Elevated — model estimates 10-50% exploitation likelihood.
Published
2026-09-29 09:00 UTC
CWE-98

Weakness classes (CWE)

  • CWE-98Variant

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')

    The PHP application receives input from an upstream component, but it does not restrict or incorrectly restricts the input before its usage in "require," "include," or similar functions.

    cwe.mitre.org →

Public exploit references

Public proof-of-concepts and detection templates for this vulnerability. Maturity ranges from reported PoCs through working detection scripts up to fully weaponized exploit modules. NEOSEC mirrors the code internally for forensic analysis; externally we only link to the original sources.

References & sources

Reanalysis & status changes

Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.

  1. Initial Analysis2026-09-28 12:20 UTC· nvd@nist.gov
    • CPE Configuration: OR *cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:* versions from (including) 4.8 up to (excluding) 4.8.32 *cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:* versions from (including) 4.9 up to (excluding) 4.9.33 *cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:* versions from (including) 5.0 up to (excluding) 5.0.29 *cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:* versions from (including) 5.1 up to (excluding) 5.1.26 *cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:* versions from (including) 5.2 up to (excluding) 5.2.28 *cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:* versions from (including) 5.3 up to (excluding) 5.3.25 *cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:* versions from (including) 5.4 up to (excluding) 5.4.23 *cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:* versions from (including) 5.5 up to (excluding) 5.5.22 *cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:* versions from (including) 5.6 up to (excluding) 5.6.21 *cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:* versions from (including) 5.7 up to (excluding) 5.7.19 *cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:* versions from (including) 5.8 up to (excluding) 5.8.17 *cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:* versions from (including) 5.9 up to (excluding) 5.9.18 *cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:* versions from (including) 6.0 up to (excluding) 6.0.16 *cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:* versions from (including) 6.1 up to (excluding) 6.1.14 *cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:* versions from (including) 6.2 up to (excluding) 6.2.13 *cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:* versions from (including) 6.3 up to (excluding) 6.3.12 *cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:* versions from (including) 6.4 up to (excluding) 6.4.12 *cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:* versions from (including) 6.5 up to (excluding) 6.5.12 *cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:* versions from (including) 6.6 up to (excluding) 6.6.9 *cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:* versions from (including) 6.7 up to (excluding) 6.7.9 *cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:* versions from (including) 6.8 up to (excluding) 6.8.10 *cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:* versions from (including) 6.9 up to (excluding) 6.9.9 *cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:* versions from (including) 7.0 up to (excluding) 7.0.6 *cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:* versions up to (excluding) 4.7.37 *cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:* versions from (including) 7.1 up to (excluding) 7.1.2
    • Reference Type: HackerOne: https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-7hp8-65ch-5whp Types: Vendor Advisory
    • Reference Type: CISA-ADP: https://patchstack.com/articles/cve-2026-87902-attackers-started-probing-wordpress-sites-hours-after-the-patch/ Types: Third Party Advisory
    • Reference Type: CISA-ADP: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-87902 Types: US Government Resource
  2. CVE Modified2026-09-26 04:17 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
    • SSVC: {"id":"CVE-2026-87902","role":"CISA Coordinator","options":[{"exploitation":"active"},{"automatable":"no"},{"technica…
    • SSVC: {"id":"CVE-2026-87902","role":"CISA Coordinator","options":[{"exploitation":"active"},{"automatable":"no"},{"technica…
  3. CVE CISA KEV Update2026-09-25 22:00 UTC· 9119a7d8-5eab-497f-8521-727c672e3725
    • Date Added: 2026-09-25
    • Due Date: 2026-09-25
    • Required Action: 2026-09-25
    • Vulnerability Name: 2026-09-25
  4. CVE Modified2026-09-25 20:17 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
    • Reference: https://patchstack.com/articles/cve-2026-87902-attackers-started-probing-wordpress-sites-hours-after-the-patch/
    • Reference: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-87902
    • SSVC: {"id":"CVE-2026-87902","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalI…
    • SSVC: {"id":"CVE-2026-87902","role":"CISA Coordinator","options":[{"exploitation":"active"},{"automatable":"no"},{"technica…
  5. New CVE Received2026-09-22 17:17 UTC· support@hackerone.com
    • Description: An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the active theme directories. If relevant pre-conditions for both the server and the active theme are met, this can lead to RCE.
    • CWE: CWE-98
    • Affected: New affected value received. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/87xxx/CVE-2026-87902.json">CVE-2026-87902</a>
    • Reference: https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-7hp8-65ch-5whp

Linked advisories