12:30PM, 24 September 2026
TLP Rating:
CVE-2026-87902 Affecting WordPress
CVE-2026-87902 is an unauthenticated path traversal vulnerability in the WordPress get_page_template() function. Under certain conditions, this vulnerability could lead to remote code execution.
The NCSC encourages organisations in New Zealand that use the affected products to review the advisory and apply the remediation as soon as possible. We also urge affected organisations to investigate unauthorised access or compromise of the affected products.
What's happening
Systems affected
What this means
What to look for
How to tell if you're at risk
What to do
Prevention
Mitigation
More information
Read more about this alert on the vendor website:
CVE-2026-87902 - WordPress External Link
If you require more information or further support, submit a report on our website: