WordPress Core Path Traversal Leading to Remote Code Execution Vulnerability
Release Date: 28th September 2026 (Added 6th October 2026)
Impact : CRITICAL
TLP Rating: Clear 
The Department of Communications and Digital Transformation (DCDT) through CERT Vanuatu (CERTVU), provides the following advisory.
This alert is relevant to Organizations and System/Network administrators that operate WordPress websites, including government, business, and community sites. This alert is intended to be understood by technical users and systems administrators.
What is it?
CVE-2026-87902 is a path traversal vulnerability in the way WordPress core resolves page templates. A specially crafted request can make WordPress include an arbitrary PHP file already present on the server, without any authentication.
Remote code execution depends on server conditions: the active theme's top-level directory name must start with "page-", the web server account must be able to read the target PHP file, and the PHP setting register_argc_argv must be enabled, which allows the known pearcmd.php technique to turn file inclusion into command execution.
What are the systems affected?
The following WordPress versions are affected:
WordPress 4.7.0 through 7.1.1, on sites where the conditions described above are met – (Affected)
Not affected / patched versions:
WordPress 7.1.2 or later (released 22 September 2026) – (Not affected)
Patched point releases for older branches (back to 4.7.x) published by the WordPress security team – (Not affected)
What does this mean?
Successful exploitation may allow attackers to:
- Include and run an arbitrary PHP file on the web server without logging in
- Execute commands on the server, install web shells, and deface or take over the website
- Access the site database and credentials, and use the server to attack other systems
Mitigation process?
CERTVU recommends the following:
-
Update WordPress Immediately
Update to WordPress 7.1.2 or later, or to the patched release for your branch. Confirm that automatic background updates actually applied. -
Reduce Exposure While Updating
-
Remove What You Do Not Need
-
Hunt for Compromise
-
Restore and Rotate if Compromised
If compromise is suspected, restore from a clean backup, rotate administrator, database, and API credentials, and report the incident to CERTVU.
Reference
- https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-7hp8-65ch-5whp
- https://www.securityweek.com/critical-wordpress-vulnerability-exploited-immediately-after-disclosure/
- https://nvd.nist.gov/vuln/detail/CVE-2026-87902
- Download advisory (English): WordPress Core Path Traversal Leading to Remote Code Execution Vulnerability