Web Hack List

Preliminary research

CVE-2026-87902: WordPress file inclusion and conditional code execution

CVE-2026-87902: Critical WordPress file inclusion and conditional RCE — Robert Ressl

AI-collected research leads through 24 September 2026, including targeted additions between broader sweeps. Unranked, incomplete, not community-vetted, and subject to change.

Anonymous page queries preserve encoded traversal until template resolution, where late decoding allows local PHP inclusion outside theme roots. The demonstrated PEAR execution chain requires a suitable page-prefixed theme directory, readable PEAR files, web-runtime argv support and a writable destination; execution remains at PHP account privilege.

Record

Document
CVE-2026-87902: Critical WordPress file inclusion and conditional RCE — Robert Ressl
Researcher
Robert Ressl
Published by
Robert Ressl
Date
Format
Advisory
Topic
Other

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Robert Ressl, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .