WordPress Security Update Advisory (CVE-2026-87902)

WordPress Security Update Advisory (CVE-2026-87902)

WordPress Security Update Advisory.


  • CVE-2026-87902, a vulnerability in WordPress that allows PHP files to be included through page template path traversal, has been resolved.
  • Follow the instructions on the reference site to update to the latest version with the Vulnerability Patch.
  • Affected Versions include various WordPress versions ranging from 4.7.0 Through 7.1.1.
  • After applying the patch, the versions are 4.7.37 Or later, 4.8.32 Or later, 4.9.33 Or later, 5.0.29 Or later, 5.1.26 Or higher, 5.2.28 Or higher, 5.3.25 Or higher, 5.4.23 Or higher, 5.5.22 Or higher, 5.6.21 Or higher, 5.7.19 Or higher, 5.8.17 Or higher, 5.9.18 Or higher, 6.0.16 Or higher, 6.1.14 Or higher, 6.2.13 Or higher, 6.3.12 Or higher, 6.4.12 Or later, 6.5.12 Or later, 6.6.9 Or later, 6.7.9 Or later, 6.8.10 Or later, 6.9.9 Or later, 7.0.6 Or later, and 7.1.2 Or later.
  • The report does not specify any additional attackers, malware, or incidents of damage other than CVE-2026-87902.