WordPress 7.1.2 fixes CVE-2026-87902, a page-template bug exploited within three days
Code execution needs a theme with a page- directory and a usable PHP file on the server; the advisory names both, and both can be checked.
WordPress released 7.1.2 on Tuesday, September 22, with a one-line explanation of why: "This security release features a fix for a critical severity security vulnerability." The fix went out the same day on every branch still receiving security fixes, back to 4.7. Three days later, on September 25, CISA added the flaw, CVE-2026-87902, to its Known Exploited Vulnerabilities catalog.
What was fixed
The advisory (GHSA-7hp8-65ch-5whp) describes the bug in two sentences:
An unauthenticated attacker can make
WordPress security advisory GHSA-7hp8-65ch-5whpget_page_template()page-template resolution include a chosen readable local.phpfile outside the active theme directories. If relevant pre-conditions for both the server environment and the active theme are met, this can lead to RCE.
It is filed as CWE-98, PHP file inclusion. WordPress scores it 9.2 under CVSS 4.0, with the vector field AT:P: attack requirements present. CISA's own CVSS 3.1 score in the CVE record is 8.1, with high attack complexity. Both reflect the same point: the include itself needs no login, but code execution depends on what is on the box.
The affected range is every release from 4.7.0 through 7.1.1. Fixed versions include 7.1.2, 7.0.6, 6.9.9, 6.8.10, 6.7.9 and 6.6.9, and the advisory lists a patched point release for each branch down to 4.7.37. The release post adds a caveat for anyone relying on backports: "only the most recent version of WordPress is actively supported."
The two preconditions
The advisory names both conditions for code execution, and each is something an administrator can check.
The theme. "The active child or parent theme contains a top-level directory whose name starts with page- (e.g. page-templates)." The advisory says this covers the legacy Twenty Twelve and Twenty Fourteen themes, "as well as some popular third party themes such as Neve, Hestia, and Sydney."
The server. A usable PHP file has to exist and be readable by the web server account. The advisory names PEAR's pearcmd.php as the well-known route "when register_argc_argv is set to On," and says two common setups qualify: "The official php image for Docker is affected, and the default cPanel configuration is affected when PHP prior to 8.5 is in use."
Exploited within days
CISA's catalog entry, added September 25, set a due date of September 28 for federal civilian agencies and marks forensic triage as required. CISA's SSVC assessment in the CVE record reads: exploitation "active," automatable "no," technical impact "total." The "no" on automation fits the preconditions: a scanner cannot know in advance whether a given site's theme and PHP configuration line up.
The timestamps are tight. The GitHub advisory was published at 13:57 UTC on September 22 and the CVE record at 16:44 UTC. CISA does not say when exploitation began.
What to do
- Update. The release post notes that sites with automatic background updates will update on their own. Anything pinned, containerized or managed by hand needs a check.
- Check the theme (parent and child) for a top-level directory beginning with
page-. A site without one does not meet the advisory's first condition, though the file inclusion itself is still fixed only by the update. - Check PHP. Our reading of the advisory, not its instruction: setting
register_argc_argvtoOfffor web requests and keeping PEAR off web-served PHP installs removes the specific path it names. It does not close the bug. - Look back. CISA requires federal agencies to run forensic triage on this one. A site that ran a vulnerable version with a
page-directory after September 22 deserves the same look: unfamiliar admin users, new PHP files, changed theme files.
Primary sources: WordPress 7.1.2 Release, GHSA-7hp8-65ch-5whp, CVE-2026-87902 record, CISA KEV alert, September 25, CISA KEV catalog, read 2026-09-29.