POCBIT

Telegram — New PoC releases & critical CVE alerts

You can join our Telegram channel to get instant updates on new PoC releases and critical CVE alerts.

Join @pocbit
WordPresscritical

CVE-2026-87902 — WordPress Core get_page_template() Unauthenticated LFI → RCE (PEAR chain)

October 2, 2026 · 79 views

WordPress core 4.7.0–7.1.1: pagename from POST used in get_page_template() without validate_file(); page-templates/ traversal + PEAR gadget → RCE. GHSA-7hp8-65ch-5whp, CVSS 4.0 9.8, CWE-22. Fixed 7.1.2+ (backports 6.8.10, 7.0.6). Python mass scanner: --check, --rce, --shell. Upstream: MRdark-ops/CVE-2026-87902 (HackfutSecRoot).

#wordpress#core#lfi#path-traversal#rce#cwe-22#unauthenticated#critical#pear

CVE:

CVE-2026-87902

Date:

2026-10-02

Severity:

CRITICAL

Exploit source

Full PoC repository on GitHub (public).

Description

Overview

CVE-2026-87902 — WordPress core — unauthenticated local file inclusion in wp-includes/template.php:get_page_template() that can escalate to remote code execution via a PEAR gadget chain (GHSA-7hp8-65ch-5whp, CVSS 4.0 9.8, CWE-22).

| | | |---|---| | Affected | WordPress 4.7.0 → 7.1.1 | | Fixed | ≥ 7.1.2 (also 6.8.10, 7.0.6 backports) | | Auth | None for LFI trigger | | Vector | pagename query var (e.g. POST) → page-templates/ traversal without validate_file() |

Public tooling mirrored on PoCbit from community research. Upstream repository: MRdark-ops/CVE-2026-87902 (author HackfutSecRoot). Also referenced as HackfutSecRoot/CVE-2026-87902 in upstream README.

PoC page: https://pocbit.org/pocs/cve-2026-87902

CVE.org: CVE-2026-87902

Attack chain (summary)

  1. Anonymous POST with page_id + crafted pagename under page-templates/ traversal.
  2. LFI confirmed (e.g. OPML oracle / wp-links-opml.php).
  3. Optional PEAR config-create gadget → shell / file manager deployment.

Practical exploitation may require theme layout preconditions (real page-* path under active theme) and PEAR/register_argc_argv environment factors—treat mass scanner output as signals, not guaranteed compromise.

Bundled tool (Python 3.8+)

Download cve-2026-87902.py — extracts the XWP_RCE/ tree from upstream.

python cve-2026-87902.py
cd XWP_RCE

python main.py -u https://target.example --check
python main.py -l targets.txt --check --threads 20
python main.py -l targets.txt --rce --shell --threads 10
python main.py -u https://target.example --rce --command "id"

Outputs (per upstream): results.txt, vulnerable.txt, rce.txt, shells.txt.

Mitigation

  1. Upgrade WordPress to 7.1.2+ or applicable backport for your branch.
  2. WAF: block pagename containing ../ or encoded traversal.
  3. register_argc_argv = Off in php.ini (reduces PEAR chain reach); remove unused pearcmd.php.

See WordPress security checklist (2026) and how to prioritize critical CVEs.

Legal and ethical use

Authorized security testing only.

References

Related PoCs

Same platform, vendor, or tags — explore more write-ups on Pocbit.

Browse full PoC archive →