WordPress Core Path Traversal Leading to Remote Code Execution Vulnerability

Release Date: 28th September 2026 (Added 6th October 2026)

Impact : CRITICAL

TLP Rating: Clear

The Department of Communications and Digital Transformation (DCDT) through CERT Vanuatu (CERTVU), provides the following advisory.

This alert is relevant to Organizations and System/Network administrators that operate WordPress websites, including government, business, and community sites. This alert is intended to be understood by technical users and systems administrators.

What is it?

CVE-2026-87902 is a path traversal vulnerability in the way WordPress core resolves page templates. A specially crafted request can make WordPress include an arbitrary PHP file already present on the server, without any authentication.

Remote code execution depends on server conditions: the active theme's top-level directory name must start with "page-", the web server account must be able to read the target PHP file, and the PHP setting register_argc_argv must be enabled, which allows the known pearcmd.php technique to turn file inclusion into command execution.

Reference

  1. https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-7hp8-65ch-5whp
  2. https://www.securityweek.com/critical-wordpress-vulnerability-exploited-immediately-after-disclosure/
  3. https://nvd.nist.gov/vuln/detail/CVE-2026-87902