CVE lookup
CVE-2026-87902
Pruva has a verified reproduction for CVE-2026-87902: WordPress Core unauthenticated path traversal in get_page_template() page-template resolution leading to conditional RCE. The canonical evidence record is REPRO-2026-00356.
REPRO
REPRO-2026-00356
Package
WordPress/wordpress-develop · github
Severity
CRITICAL
Status
published