CVE-2026-87902 Scanner
CVE-2026-87902 Scanner - Path Traversal vulnerability in WordPress Core
Used 3 times · 5.9k assets checked · domain, subdomain, ipv4
An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the active theme directories. If relevant pre-conditions for both the server and the active theme are met, this can lead to RCE.
CVE-2026-87902 Scanner - Path Traversal vulnerability in WordPress Core
Used 3 times · 5.9k assets checked · domain, subdomain, ipv4
S4E maps published CVEs to scanners and forecasts the next disclosure window for your stack.
Create a free account →