Atrilya
All analyses
WordPressCriticalReference · CVE-2026-87902CVSS 9.2

CVE-2026-87902: WordPress includes an arbitrary PHP file through the page template

Published

On 22 September 2026 WordPress fixed CVE-2026-87902, an unauthenticated path traversal in page-template resolution rated 9.2. A visitor with no account can force WordPress to include a readable PHP file located outside the active theme. Patchstack observed probing and PHP file-write attempts from the moment the patch dropped.

Where does the patch stand?

Fixed: WordPress 7.1.2 and 7.0.6 (backport down to 4.7.37), 22 September 2026

What does this flaw actually do?

The flaw lives in page-template selection. By sending a `page_id` pointing to an existing page and a `pagename` carrying an encoded path traversal, the attacker hijacks `get_page_template()`: WordPress then includes a readable PHP file located outside the active theme.

The core primitive is local file inclusion (LFI), not unconditional code execution. Execution becomes possible when a controllable PHP file already exists on the server (an upload, a poisoned log, a session). No authentication, no account, no vulnerable plugin required.

How does the attack slip past filters?

The payload travels in both GET and POST. Traversal depth ranges from one to twelve levels to cope with different theme and install layouts.

The encoding is deliberately varied: uppercase and lowercase hex, single and double encoding. A filter that only looks for a plain `../` lets most of these variants through.

Why is it urgent?

Patchstack recorded the first probing and PHP file-write requests on patch day itself; exploitation traffic rose tenfold within days. The flaw was added to the CISA KEV catalog.

WordPress runs a large share of the web: every version from 4.7.0 to 7.1.1 is affected. The window between the fix being published and deployed on each site is the real risk window.

What should you do now?

Update WordPress to 7.1.2, 7.0.6, or your branch’s backported release (down to 4.7.37). Then audit writable directories (uploads, cache) for unexpected PHP files.

Filter requests carrying an encoded path traversal in `page_id`/`pagename` at the edge, in GET and POST alike: that is exactly what a virtual patch is for, until the update is everywhere.

Who is affected?

  • WordPress Core 4.7.0 to 7.1.1: unauthenticated local PHP file inclusion
  • CVSS v4.0: 9.2 (critical). Added to the CISA KEV catalog
  • Fixed in 7.1.2 (7.1 branch) and 7.0.6 (7.0 branch), backported down to 4.7.37
  • Probing and PHP file-write attempts seen from patch day (22 September 2026)

How does AtriShield stop it?

Virtual patch: the flaw is neutralised at the entrance of your server, without changing your application and without waiting for a maintenance window. Decisions and logs stay inside your infrastructure.

  • ✓Virtual patch at the edge: requests carrying an encoded path traversal in `page_id`/`pagename` are cut before WordPress, in GET and POST alike.
  • ✓Encoding variants (upper/lowercase hex, single and double) are normalised and rejected, not just a plain `../`.
  • ✓No change to your theme or your code: protection is added at the edge, with no redeployment.
  • ✓WordPress’s fix still has to be applied: the virtual patch covers the gap, it does not replace it.
Exploit→AtriShield×Magento

Sources

Analysis published by Atrilya Solutions, based on public security reporting. The links above point to the original sources.

More analyses

Running an exposed server?

We review your exposure together (which applications, which versions, how much surface), then switch AtriShield on in observe mode: you see what would be blocked before anything is.

Talk to an Atrilya Solutions engineer