Preliminary research
CVE-2026-87902: WordPress file inclusion and conditional code execution
CVE-2026-87902: Critical WordPress file inclusion and conditional RCE — Robert Ressl
AI-collected research leads through 24 September 2026, including targeted additions between broader sweeps. Unranked, incomplete, not community-vetted, and subject to change.
Anonymous page queries preserve encoded traversal until template resolution, where late decoding allows local PHP inclusion outside theme roots. The demonstrated PEAR execution chain requires a suitable page-prefixed theme directory, readable PEAR files, web-runtime argv support and a writable destination; execution remains at PHP account privilege.
Record
- Document
- CVE-2026-87902: Critical WordPress file inclusion and conditional RCE — Robert Ressl
- Researcher
- Robert Ressl
- Published by
- Robert Ressl
- Date
- Format
- Advisory
- Topic
- Other
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Robert Ressl, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .