CVE-2026-87902 in WordPress Enables Conditional RCE Security updates released for WordPress address CVE-2026-87902, a severe unauthenticated path traversal flaw within its page-template resolution mechanism. The weakness allows the CMS to load arbitrary readable PHP files outside designated theme directories, potentially resulting in Remote Code Execution (RCE) under tailored server and theme setups.

Read the full article at SOCRadar →