Code Defence Cyber security

Critical WordPress page template resolution vulnerability CVE-2026-87902 actively exploited in the wild

Active wild exploitation targeting core web publishing platform routines has been detected across global web application firewall networks within hours of public disclosure. Unauthenticated remote actors manipulate query parameters to force local file inclusion and execute arbitrary PHP code.

The vulnerability, tracked as CVE-2026-87902 with a CVSS score of 9.2, impacts core WordPress installations prior to maintenance update releases. The flaw stems from insufficient input sanitization within the get_page_template() function during template file resolution. Unauthenticated remote adversaries transmit crafted HTTP requests to manipulate resolution paths, forcing the web server process to load user-controlled local files containing PHP code, dropping persistent web shells directly into web hosting paths. Threat monitoring sensors recorded automated scanning sweeps targeting exposed public sites.

Subverting central web publishing platforms provides adversaries with immediate initial access and remote code execution over web hosting infrastructure. Armed with web shell footholds, threat actors can extract database configuration keys, harvest user session tokens, and deploy secondary malware droppers across hosted environments.

– Deploy core WordPress maintenance updates immediately across all self-hosted and managed site deployments.

– Configure web application firewall rules to intercept HTTP GET and POST requests containing path traversal payloads targeting template resolution endpoints.

– Restrict PHP script execution rights within wp-content/uploads and temporary media storage directories across web server configurations.

– Inspect web hosting directories for unauthorized PHP files created during recent automated exploitation sweeps.

Web application perimeter defense demands rigid path sanitization and continuous upload directory auditing to ensure public web publishing platforms remain protected from unauthenticated local file inclusion exploits. #CodeDefence #WordPress #RCE #LocalFileInclusion #WebSecurity #AppSec #PatchManagement #ZeroDay
/

Scroll to Top