CVE-2026-87902
HIGH
NVD
CVSS Score
8.1
Severity
HIGH
Published
Sep 22, 2026
Vendor
unknown
Description
An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the active theme directories. If relevant pre-conditions for both the server and the active theme are met, this can lead to RCE.