Skip to content

CVE lookup

CVE-2026-87902

Pruva has a verified reproduction for CVE-2026-87902: WordPress Core unauthenticated path traversal in get_page_template() page-template resolution leading to conditional RCE. The canonical evidence record is REPRO-2026-00356.

REPRO

REPRO-2026-00356

Package

WordPress/wordpress-develop · github

Severity

CRITICAL

Status

published