SPOJENO PŘES CVE WordPress Core – Critical Path Traversal Vulnerability
Classification: Critical, Solution: Official Fix, Exploit Maturity: Proof-of-Concept, CVSSv4.0: 9.2, CVEs: CVE-2026-87902, Summary: A critical path-traversal vulnerability has been corrected in WordPress Core. An unauthenticated attacker can manipulate page-template resolution so that WordPress includes a chosen readable local PHP file outside the active theme directories. Under compatible theme and server conditions, exploitation can result in remote code execution and complete website…
EPSS 0.03 CVSS 9.2 CVE-2026-87902 WordPress FI US CA NL FR