The vulnerability claim appears in the researcher’s repository.

Researcher Abraxas Labs reported CVE-2026-87902: according to its report, WordPress Core through version 7.1.1 has an unauthenticated local file inclusion (LFI) that can include a readable local PHP file outside the active theme.

The report links the vector to the locate_template() function and the pagename URL parameter after decoding. The repository recommends updating WordPress Core to version 7.1.2 or later.

Claim check:

  • CVE-2026-87902: WordPress Core through version 7.1.1 allows unauthenticated inclusion of a readable local PHP file outside the active theme. (confirmed only by the carrying publication: evidence; «An unauthenticated attacker can make get_page_template() page-template resolution include a chosen readable local .php file outside the active theme directories. locate_template() in WordPress <= 7.1.1 concatenates the caller-supplied template name onto the theme path and does not verify the result stays inside the theme.»)
  • The report links the vector to the locate_template() function and the pagename URL parameter after decoding. (confirmed only by the carrying publication: evidence; «The core-reachable vector is the url-decoded pagename query variable. WordPress 7.1.2 adds _wp_is_template_path_allowed().»)
  • The repository recommends updating WordPress Core to version 7.1.2 or later. (confirmed only by the carrying publication: evidence; «Do this first: Update WordPress Core to 7.1.2 or newer .»)

Primary sources:

score 77.9 out of 100 · kind: incident