CVE-2026-87902 Affecting WordPress

This section contains time sensitive announcements about specific cyber threats, vulnerabilities and scams. Each alert has information you need to be aware of, and what actions to take to mitigate any risk to you or your organisation.

Subscribe to our updates to be notified as soon as we publish an alert.

12:30PM, 24 September 2026

TLP Rating: Clear

CVE-2026-87902 Affecting WordPress

CVE-2026-87902 is an unauthenticated path traversal vulnerability in the WordPress get_page_template() function. Under certain conditions, this vulnerability could lead to remote code execution.

The NCSC encourages organisations in New Zealand that use the affected products to review the advisory and apply the remediation as soon as possible. We also urge affected organisations to investigate unauthorised access or compromise of the affected products.

What's happening

Systems affected

WordPress versions before 7.1.2

What this means

WordPress 7.1.2 has been released containing a fix for the vulnerability, and as a courtesy to users on older branches the fix has been backported to all branches back to 4.7. See the vendor advisory for further details.

What to look for

How to tell if you're at risk

If you are running one of the affected products within the version range listed above.

What to do

Prevention

Upgrade the WordPress installation to a patched version.

Mitigation

Validate that the active theme resides in the correct directory and that no custom template files are located outside the theme folder; update or remove such files if necessary.
 
Implement input validation or an allow list for template paths to prevent arbitrary local file inclusion, thereby protecting against future LFI exploits in WordPress.

More information

Read more about this alert on the vendor website:

CVE-2026-87902 - WordPress External Link

If you require more information or further support, submit a report on our website:

Report an incident External Link External Link