Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The lesson from CVE-2026-87902 is to patch by branch, not by guessing from a recent version number: WordPress 7.1.1 is affected, 7.1.2 is the listed fix for the 7.1 branch, and older branches have their own fixed point releases as far back as 4.7. The flaw is reachable without authentication, but the advisory’s path to remote code execution depends on additional theme and server conditions.

What the WordPress file-inclusion bug does

The WordPress/wordpress-develop advisory tracks the vulnerability as CVE-2026-87902 and classifies it as CWE-98, improper control of a filename used in a PHP include or require statement. It credits Robert Ressl as the discoverer and responsible discloser.

In the documented path, an unauthenticated attacker can influence get_page_template() resolution so that WordPress includes a chosen readable local .php file outside the active theme directories. The advisory rates the vulnerability Critical and gives it a CVSS v4 overall score of 9.2/10. Its vector lists a network attack, low attack complexity, present attack requirements, no privileges required, and no user interaction.

File inclusion is the direct flaw; remote code execution is a conditional outcome, not an automatic result on every affected installation. The advisory’s stated theme and server prerequisites matter when assessing that route. The unauthenticated network reachability and Critical rating still make the core fix the priority.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Which WordPress versions are affected, and what fixes each branch?

The WordPress/wordpress-develop 2026 advisory lists these affected ranges and branch-specific fixed releases. Compare the complete installed version with the row for its branch; a release immediately before the fixed point release remains affected.

Branch ranges and fixes listed in the WordPress/wordpress-develop CVE-2026-87902 advisory
Branch Affected releases Fixed release listed
7.1 7.1.0–7.1.1 7.1.2
7.0 7.0.0–7.0.5 7.0.6
6.9 6.9.0–6.9.8 6.9.9
6.8 6.8.0–6.8.9 6.8.10
6.7 6.7.0–6.7.8 6.7.9
6.6 6.6.0–6.6.8 6.6.9
6.5 6.5.0–6.5.11 6.5.12
6.4 6.4.0–6.4.11 6.4.12
6.3 6.3.0–6.3.11 6.3.12
6.2 6.2.0–6.2.12 6.2.13
6.1 6.1.0–6.1.13 6.1.14
6.0 6.0.0–6.0.15 6.0.16
5.9 5.9.0–5.9.17 5.9.18
5.8 5.8.0–5.8.16 5.8.17
5.7 5.7.0–5.7.18 5.7.19
5.6 5.6.0–5.6.20 5.6.21
5.5 5.5.0–5.5.21 5.5.22
5.4 5.4.0–5.4.22 5.4.23
5.3 5.3.0–5.3.24 5.3.25
5.2 5.2.0–5.2.27 5.2.28
5.1 5.1.0–5.1.25 5.1.26
5.0 5.0.0–5.0.28 5.0.29
4.9 4.9.0–4.9.32 4.9.33
4.8 4.8.0–4.8.31 4.8.32
4.7 4.7.0–4.7.36 4.7.37

Why the exploit depends on the site’s configuration

The advisory describes a specific path to the flaw, with two relevant conditions:

  • Theme directory: The active parent or child theme has a top-level directory whose name begins with page-; page-templates is the advisory’s example. It names Twenty Twelve, Twenty Fourteen, Neve, Hestia, and Sydney as examples of themes to consider, but that is not a claim that every installation or configuration of those themes meets the condition.
  • Readable local PHP target: A chosen .php file exists on the server and is readable by the web-server account. The advisory discusses a possible PEAR-to-RCE transition via pearcmd.php when PHP’s register_argc_argv is On. It notes this setting in the official PHP Docker image and in the default cPanel configuration when PHP prior to 8.5 is used.

These requirements explain why the CVSS vector records attack requirements as present. They are not a reason to leave an affected core installation unpatched: they describe conditions in the documented exploitation route, not a substitute for the fixed release.

How to check and close the patch window

  1. Check the installed version. In the WordPress Dashboard, open Dashboard > Updates and note the installed WordPress version. If managing the site another way, use the version reported by that management system and confirm it against the site’s actual installation.
  2. Match the version to its branch. Find that branch in the table above. If the installed version is within its affected range, update to at least the fixed point release listed for that same branch. For example, 7.1.1 is not fixed; 7.1.2 is the listed 7.1 fix.
  3. Apply the core update. Use the available WordPress update in Dashboard > Updates or the site’s normal managed update process. WordPress documentation says supported automatic background updates begin automatically, but availability of an update is not proof that a particular site has installed it.
  4. Verify completion. After the update reports completion, check the installed version again and compare it with the branch’s fixed release. Record or monitor that final installed state rather than treating a published release, queued update, or successful-looking notification as confirmation by itself.

WordPress 7.1.1 illustrates why the release date alone is not enough. WordPress.org documented 7.1.1 on September 17, 2026 as a security and maintenance release, with 17 Core bug fixes, 21 Block Editor bug fixes, and 11 security fixes; its announcement recommended updating immediately because it was a security release. Those counts and that recommendation describe 7.1.1, not the later CVE-2026-87902 fix, which the advisory lists in 7.1.2. A security release can address important issues without containing a fix disclosed separately afterward.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What backports do—and do not—mean

The advisory lists fixes for maintained branches from 7.1 back to 4.7. This is useful operational coverage: a site that cannot immediately move to the newest branch may still have a corresponding point release that fixes this vulnerability. It does not mean every older WordPress release receives security fixes indefinitely.

WordPress.org’s Security policy says only the latest WordPress version is officially supported; the Security Team backports fixes to older versions as a courtesy so older sites can receive critical fixes through auto-updates. The 7.1.1 documentation likewise describes older-branch backports and says versions 4.6 and earlier no longer receive security updates. A backport closes this specific vulnerability on the listed branch when installed; it does not make that older branch officially supported or guarantee future security coverage.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What this advisory does not establish

The advisory and release information establish affected and fixed versions and describe a conditional exploitation path. They do not establish a defensible count of currently exposed sites, confirm exploitation in the wild, or provide a measured patch-adoption rate for CVE-2026-87902. WordPress.org’s statement that WordPress powers more than 43% of the web is platform-wide scale context, not a count of installations affected by this flaw.

A hosting provider or web application firewall may help coordinate a rollout or offer mitigation; WordPress describes coordination with hosting and security providers on releases and WAF mitigations. Neither should be treated as equivalent to installing the fixed core release named for the site’s branch.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.