CVE-2026-87902 in WordPress Enables Conditional RCE Security updates released for WordPress address CVE-2026-87902, a severe unauthenticated path traversal flaw within its page-template resolution mechanism. The weakness allows the CMS to load arbitrary readable PHP files outside designated theme directories, potentially resulting in Remote Code Execution (RCE) under tailored server and theme setups.
CVE-2026-87902 in WordPress Enables Conditional RCE
About this summary. This is a short, independently written summary of an article first published by SOCRadar. Cyber Security News did not report or verify the underlying story. Read the original: https://socradar.io/blog/cve-2026-87902-wordpress-conditional-rce/
Source attribution: headline and facts are from SOCRadar (socradar.io). Summary method: excerpt of the source description. See our source attribution policy.






