The vulnerability claim appears in the researcher’s repository.
Researcher Abraxas Labs reported CVE-2026-87902: according to its report, WordPress Core through version 7.1.1 has an unauthenticated local file inclusion (LFI) that can include a readable local PHP file outside the active theme.
The report links the vector to the locate_template() function and the pagename URL parameter after decoding. The repository recommends updating WordPress Core to version 7.1.2 or later.
Claim check:
- CVE-2026-87902: WordPress Core through version 7.1.1 allows unauthenticated inclusion of a readable local PHP file outside the active theme. (confirmed only by the carrying publication: evidence; «An unauthenticated attacker can make
get_page_template()page-template resolution include a chosen readable local.phpfile outside the active theme directories.locate_template()in WordPress <= 7.1.1 concatenates the caller-supplied template name onto the theme path and does not verify the result stays inside the theme.») - The report links the vector to the locate_template() function and the pagename URL parameter after decoding. (confirmed only by the carrying publication: evidence; «The core-reachable vector is the url-decoded
pagenamequery variable. WordPress 7.1.2 adds_wp_is_template_path_allowed().») - The repository recommends updating WordPress Core to version 7.1.2 or later. (confirmed only by the carrying publication: evidence; «Do this first: Update WordPress Core to 7.1.2 or newer .»)
Primary sources:
score 77.9 out of 100 · kind: incident