Critical WordPress Core Flaw Enables Unauthenticated File Inclusion
CVE-2026-87902 is a critical WordPress Core path traversal vulnerability that allows unauthenticated attackers to include readable PHP files outside the active theme directory. Successful exploitation can lead to remote code execution and complete site compromise, although it requires a compatible theme structure and a suitable local PHP file. WordPress fixed the flaw in version 7.1.2 and released security backports for every branch through 4.7. Site owners should update immediately, verify installation success, and investigate suspicious traversal requests targeting the pagename parameter.
Reference: wordfence.com