Skip to content

security_identifier

CVE-2026-87902

Catalogued WordPress core vulnerability in page-template resolution that allows an unauthenticated request to include a readable local .php file from outside the active theme directories, rated CVSS 9.2.

Known aliases

  • WordPress page-template inclusion flaw

Relationships

No evidence-backed relationships are recorded.

Current clusters

security6 publishers

WordPress patched a comment flaw that uses an admin's session to plant a web shell

CVE-2026-93485 was fixed on September 17 in WordPress 7.1.1. An anonymous comment plants a script, an administrator opens the page, and the script uploads a plugin carrying a web shell. Affected versions go back to 4.7.

Perspective Coverage

6 publishers
Builder
Builder 23%
Operator
Operator 68%
Investor
Investor 9%

Reality

Evidence60
Adoption
Insufficient
Hype gap+20
Incentives45
Confidence62