The urgent release of 22 September fixes CVE-2026-87902: an attacker with no password can make WordPress load a chosen PHP file from the server. With certain themes and server settings this can lead to remote code execution. The fix has been backported all the way to version 4.7.
- CVE-2026-87902 scores 9.2 on CVSS v4 in the WordPress advisory and requires neither an account nor any user action.
- It is dangerous if the active theme has a folder whose name starts with page-, as in Twenty Twelve, Twenty Fourteen, Neve, Hestia and Sydney.
- The second key is a PHP file on the server that can be abused, such as pearcmd.php with register_argc_argv switched on.
Two conditions have to meet for trouble. One is in your theme, the other in your server. That is why it is worth checking both, not just the version.
The hole is in the way WordPress decides which page template to load. An attacker with no account can trick it into including a PHP file outside the theme folder. That alone is bad. If both the theme and the server meet the conditions, it can lead to execution of outside code.
What to check today
First the version. If automatic updates work, the site is probably already on the patched one. If they do not, you update by hand.
Then the theme. Open its folder and see whether there is a subfolder whose name starts with page-. If you use one of the five themes listed, or a child theme of one, assume you have it.
Finally the server. If you are on cPanel with the default configuration and PHP before 8.5, or run WordPress on the official PHP image for Docker, the server condition is met for you.
You update to 7.1.2 or to the patched release of your branch. Today, before someone else has read the same advisory.