Remote Code Execution Vulnerability (CVE‑2026‑87902) Discovered in WordPress < 7.1.2
What Happened – A newly disclosed flaw (CVE‑2026‑87902) in WordPress allows an unauthenticated attacker to manipulate the page‑template resolution logic and execute arbitrary PHP files outside the active theme directory. Exploit code is already public and the vulnerability is listed in CISA’s Known Exploited Vulnerabilities (KEV) catalog.
Why It Matters for Trust & Control Assurance
- The scenario directly tests an organization’s vulnerability‑management and patch‑management controls – a core control objective that, when continuously monitored, provides defensible evidence for multiple frameworks.
- Demonstrating timely remediation (evidence of patch deployment, automated scanning, and documented remediation processes) is the exact proof points auditors look for when assessing control assurance.
- Continuous evidence of a robust vulnerability‑management program reduces the risk of an RCE leading to data exposure or service disruption.
Who Is Affected – Any entity that runs WordPress sites, including:
- Government agencies (large and medium)
- Large and medium businesses
- SaaS providers and technology firms that host customer‑facing WordPress installations
Recommended Actions
- Apply the WordPress 7.1.2 update (or later) immediately after testing in a staging environment.
- Formalize a documented vulnerability‑management process with defined review cycles.
- Deploy automated patch‑management and vulnerability‑scanning tools to ensure monthly (or more frequent) coverage of all WordPress assets.
- Record remediation activities in a central audit log to provide continuous evidence for compliance reviews.
Technical Notes – The flaw resides in the get_page_template() function, enabling an attacker to include a readable local .php file outside the theme directory. Successful exploitation yields Remote Code Execution (RCE) on the web server. CVE‑2026‑87902 is listed in CISA’s KEV catalog. Source: CIS Advisory 2026‑106