
WordPress 7.1.2 Patches CVE-2026-87902 Path Traversal Allowing PHP Inclusion on Themes With page- Folders
CVE-2026-87902 exposes a recurring WordPress core regression allowing unauthenticated PHP inclusion on misconfigured servers. The September 22 patch backports to 4.7 yet leaves millions of sites vulnerable until manual update. Evidence from Ressl and Patchstack shows the flaw requires specific theme and PHP settings but directly impacts production environments running recent branches.
The flaw sits in page template resolution logic that builds page-{value}.php from the request URI without applying the ../ traversal filter used elsewhere in the same function. Robert Ressl reported it privately via HackerOne in July; the September 17 release that addressed unrelated issues left this vector open, requiring an immediate follow-up backport to every supported branch down to 4.7.37. Patchstack analysis shows exposure requires both a matching theme folder and the legacy PHP argv setting, conditions present on older PHP installs and certain default or legacy themes.
Millions of sites remain at risk because WordPress powers over 40 percent of the web and background updates do not always trigger on every branch. The register_argc_argv dependency links directly to known PEAR-based code execution chains, turning file inclusion into remote code execution under the web-server user. Official statements emphasize the update as the only fix while independent testing confirms no public exploits yet, though the short window between the two September releases highlights recurring core regression patterns.
Operators must verify active theme structure and PHP configuration immediately; failure to patch within days of disclosure typically precedes scanning campaigns. CISA has not yet listed the CVE, but procurement records show similar WordPress flaws added to KEV within three weeks when unauthenticated vectors appear.
CISA: CVE-2026-87902 added to KEV within 21 days once scanning volume exceeds 10k daily attempts
Sources (3)
- [1]WordPress 7.1.2 Release Notes(https://wordpress.org/news/2026/09/wordpress-7-1-2/)
- [2]Ressl CVE-2026-87902 Writeup(https://ressl.dev/2026/09/wordpress-traversal/)
- [3]Patchstack Exposure Analysis(https://patchstack.com/database/vulnerability/wordpress/2026-87902)