POCBIT

Telegram — New PoC releases & critical CVE alerts

You can join our Telegram channel to get instant updates on new PoC releases and critical CVE alerts.

Join @pocbit
← Blog

WordPress Core LFI (CVE-2026-87902): get_page_template(), pagename, and PEAR RCE Chains

Admin · October 3, 2026 · 7 views

Core WordPress bugs change every install’s risk profile

Plugin CVEs dominate headlines, but CVE-2026-87902 is WordPress core: unauthenticated local file inclusion in get_page_template() (GHSA-7hp8-65ch-5whp, CVSS 4.0 9.8, CWE-22). Affected releases span 4.7.0 through 7.1.1; fixes land in 7.1.2+ with branch backports such as 6.8.10 and 7.0.6.

Mechanism summary and mirrored scanner tooling: CVE-2026-87902 on pocbit.org. Community upstream: MRdark-ops/CVE-2026-87902.

What broke in template loading

wp-includes/template.php builds a page template path using the public pagename query variable—including values supplied via POST in some request flows. In vulnerable builds, that path is not passed through validate_file() before locate_template() resolves it with file_exists().

When the active theme exposes a real page-* hierarchy under page-templates/, attackers can traverse with ../ segments and include attacker-chosen files already on disk (for example wp-links-opml.php as an oracle). Public exploit chains then discuss PEAR config-create gadget escalation toward RCE—environment-dependent (register_argc_argv, presence of pearcmd.php, theme layout).

Treat “LFI confirmed” and “RCE achieved” as separate maturity stages in your runbook.

Defender checklist

| # | Action | Detail | |---|--------|--------| | 1 | Inventory WordPress core version | Every site—not only plugin-heavy stacks | | 2 | Upgrade to patched branch | ≥ 7.1.2 or vendor backport for your line | | 3 | Emergency WAF | Block pagename containing ../, %2e%2e, or encoded traversal | | 4 | PHP hardening | register_argc_argv = Off; remove unused PEAR tooling | | 5 | Monitor | Spikes in POSTs with page_id + odd pagename before core patch window closes |

Cross-read: WordPress security checklist (2026), how to prioritize critical CVEs, RCE vs local privilege escalation.

Blue-team expectations for mass scanners

Community scanners report vulnerable version, LFI oracle, possibly vulnerable, and patched skip states. False negatives appear when themes lack exploitable template directories, when caches normalize requests, or when PEAR gadgets are unavailable.

Use scan output to prioritize patch cadence, not as proof of compromise without corroborating logs.

Patch validation in a lab

  1. Snapshot a vulnerable core VM with a theme that matches public PoC preconditions.
  2. Run --check mode from the PoC page bundle in an isolated network.
  3. Upgrade core to the fixed minor; repeat—expect patched fingerprint or failed traversal.

See safe PoC lab setup and CVE PoC testing step-by-step.

FAQ

We auto-update minor releases—are we done?

Verify actual deployed version on each property (multisite, Bedrock forks, managed hosts lagging).

Does disabling plugins help?

This is core—plugin count does not remove the vulnerable template loader. Patch core.

Bottom line

CVE-2026-87902 is why platform version belongs in the same dashboard as plugin CVEs. Patch WordPress core on a schedule you can defend, layer WAF during rollout, and validate with authorized check tooling—not internet-wide spray.