Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-87902

An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the active theme directories. If relevant pre-conditions for both the server and the active theme are met, this can lead to RCE.
Exploit prediction scoring system (EPSS) score
CVSS Severity
CVSS v3 Score 8.1


Contact Us

Shodan ® - All rights reserved