# WordPress vulnerabilities in 2026, CVE-2026-87902, wp2shell and the safe version per branch (/en/blog/wordpress-vulnerabilities-2026)



WordPress 7.1.2 shipped on 22 September 2026 with a single fix, and attackers were sending requests for it the same day. Three days later CISA added the bug, CVE-2026-87902, to its catalog of known exploited vulnerabilities. It is the second WordPress core flaw this year to go from patch to active exploitation within days, after wp2shell in July.

This page covers CVE-2026-87902 first: what it is, which versions are affected, the fixed version for every branch, and the conditions that turn it into code execution. Then it lists every WordPress core security release of 2026, the plugin flaws attackers exploited at scale, and how to check which version a site really runs. We update it as new advisories land.

## The WordPress vulnerability of 2026, CVE-2026-87902 [#the-wordpress-vulnerability-of-2026-cve-2026-87902]

CVE-2026-87902 is an unauthenticated path traversal in page-template resolution, in `wp-includes/template.php`. WordPress builds a list of candidate template files from the requested page, and the candidate built from the `pagename` value was not validated like the others. An attacker can make WordPress include a readable `.php` file from outside the active theme directories. Robert Ressl reported it.

|                |                                                                                                                                                                   |
| -------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| CVE            | [CVE-2026-87902](https://www.cve.org/CVERecord?id=CVE-2026-87902)                                                                                                 |
| Type           | Path traversal leading to conditional remote code execution (CWE-98)                                                                                              |
| Authentication | None                                                                                                                                                              |
| Severity       | Critical, 9.2 under CVSS 4.0 as scored by [Patchstack](https://patchstack.com/articles/wordpress-7-1-2-security-release-unauthenticated-lfi-to-rce/)              |
| Affected       | WordPress 4.7.0 to 7.1.1                                                                                                                                          |
| Fixed          | 7.1.2, released 22 September 2026, with fixes for every branch back to 4.7                                                                                        |
| Exploited      | Yes. Added to the [CISA KEV catalog](https://www.cisa.gov/news-events/alerts/2026/09/25/cisa-adds-one-known-exploited-vulnerability-catalog) on 25 September 2026 |

### Which version is safe for each branch [#which-version-is-safe-for-each-branch]

WordPress released the fix for every branch from 4.7 up. Only the latest version is actively supported, but these are the first safe releases if you are on an older line:

| Branch | Fixed in | Branch        | Fixed in            |
| ------ | -------- | ------------- | ------------------- |
| 7.1    | 7.1.2    | 5.8           | 5.8.17              |
| 7.0    | 7.0.6    | 5.7           | 5.7.19              |
| 6.9    | 6.9.9    | 5.6           | 5.6.21              |
| 6.8    | 6.8.10   | 5.5           | 5.5.22              |
| 6.7    | 6.7.9    | 5.4           | 5.4.23              |
| 6.6    | 6.6.9    | 5.3           | 5.3.25              |
| 6.5    | 6.5.12   | 5.2           | 5.2.28              |
| 6.4    | 6.4.12   | 5.1           | 5.1.26              |
| 6.3    | 6.3.12   | 5.0           | 5.0.29              |
| 6.2    | 6.2.13   | 4.9           | 4.9.33              |
| 6.1    | 6.1.14   | 4.8           | 4.8.32              |
| 6.0    | 6.0.16   | 4.7           | 4.7.37              |
| 5.9    | 5.9.18   | 4.6 and older | No fix, unsupported |

### When it becomes remote code execution [#when-it-becomes-remote-code-execution]

The traversal alone lets an attacker include a `.php` file that already exists on the server. According to Patchstack's analysis, turning that into code execution needs three conditions at once:

1. **The active theme has a top-level directory whose name starts with `page-`.**
2. **PHP runs with `register_argc_argv` enabled.** It is on in the official Docker images and in cPanel with PHP below 8.5.
3. **A usable `.php` file is readable on the server**, typically PEAR's `pearcmd.php`.

The exploitation reported so far follows this path. The Hacker News, citing Patchstack and Previdian, describes attackers using `pearcmd.php` to write PHP files to `/tmp` and `/var/tmp` within hours of the release.

### Am I affected? [#am-i-affected]

* **Your WordPress version is between 4.7.0 and 7.1.1**, and not one of the fixed releases in the table: you are affected by the traversal. Update.
* **You also match the three conditions above:** an attacker can run code on your server. Treat the site as possibly compromised if it stayed unpatched after 22 September, and look for unexpected PHP files in `/tmp`, `/var/tmp`, and your uploads directory.
* **You run 4.6 or older:** there is no fix for your line. Upgrade to a supported version.

### What to do [#what-to-do]

1. **Update to 7.1.2**, or to the fixed release of your branch. WordPress installs minor releases like this one automatically by default, so check that the update actually landed: a host or a plugin can turn background updates off.
2. **Check the three conditions** even after updating, because they also matter for the next include bug. Disable `register_argc_argv` if nothing on the server needs it, and remove PEAR if you do not use it.
3. **Look for traces** if the site was exposed: new PHP files in temporary and upload directories, new admin accounts, and requests with `pagename` values containing `../` in your access logs.

## Every WordPress core security release of 2026 [#every-wordpress-core-security-release-of-2026]

| Date           | Release                                                                                     | Main issue                                                                                                                                                                                      | Severity                         | Fixed in                                 |
| -------------- | ------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------- | ---------------------------------------- |
| 10 to 11 March | [6.9.2, 6.9.3, 6.9.4](https://wordpress.org/documentation/wordpress-version/version-6-9-4/) | Ten fixes, including a blind SSRF, stored XSS, an authorization bypass, a PclZip path traversal and an XXE in getID3. 6.9.2 broke some sites, and 6.9.4 completed the fixes the next day        | Mixed                            | 6.9.4                                    |
| 17 July        | [7.0.2](https://wordpress.org/news/2026/07/wordpress-7-0-2-release/)                        | wp2shell, CVE-2026-63030 and CVE-2026-60137, an unauthenticated chain from REST API batch-route confusion and SQL injection to code execution. Exploited within days, in CISA KEV since 21 July | Critical, 9.8 for CVE-2026-63030 | 7.0.2, 6.9.5, 6.8.6 (SQL injection only) |
| 6 August       | [7.0.3](https://wordpress.org/documentation/wordpress-version/version-7-0-3/)               | Twelve fixes. The headline is CVE-2026-64638, an unauthenticated reflected XSS on the login screen that can lead to PHP code execution                                                          | High, 8.9 for CVE-2026-64638     | 7.0.3, every branch to 4.7.34            |
| 12 August      | [7.0.4](https://wordpress.org/documentation/wordpress-version/version-7-0-4/)               | CVE-2026-65640, code execution by an Author or above through a malicious upload on sites using Imagick and Ghostscript                                                                          | High                             | 7.0.4, every branch to 4.7.35            |
| 19 August      | 7.1                                                                                         | Major release                                                                                                                                                                                   |                                  |                                          |
| 17 September   | [7.1.1](https://wordpress.org/documentation/wordpress-version/version-7-1-1/)               | Eleven fixes, including an unauthenticated stored XSS through paragraph formatting (subject to comment approval) and an authenticated path traversal in the REST API templates controller       | Mixed                            | 7.1.1, 7.0.5, every branch to 4.7.36     |
| 22 September   | [7.1.2](https://wordpress.org/documentation/wordpress-version/version-7-1-2/)               | CVE-2026-87902, the page-template path traversal above. In CISA KEV since 25 September                                                                                                          | Critical                         | 7.1.2, every branch to 4.7.37            |

wp2shell is the other release that deserves its own note. It affected 6.9.0 to 6.9.4 and 7.0.0 to 7.0.1 in their default configuration, and the WordPress team forced the update through the auto-update system on sites running affected versions. If your 7.0 site was frozen on 7.0.1 in July, it was exposed to a chain that needed no account and no plugin.

## The plugin flaws attackers exploited in 2026 [#the-plugin-flaws-attackers-exploited-in-2026]

Core gets the headlines, but most compromised WordPress sites in 2026 came through plugins. Three critical, unauthenticated flaws were exploited at scale:

| Plugin                             | CVE                                                                                                                                  | Issue                                                                                                                                            | Fixed in |
| ---------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------ | -------- |
| Everest Forms Pro                  | [CVE-2026-3300](https://www.infosecurity-magazine.com/news/everest-forms-pro-rce-actively/)                                          | Form values from the Complex Calculation feature reach `eval()`, so a crafted submission runs PHP. Wordfence reports exploitation from mid-April | 1.9.13   |
| WooCommerce Wholesale Lead Capture | [CVE-2026-27540](https://thehackernews.com/2026/09/attackers-exploit-woocommerce-wholesale.html)                                     | Arbitrary file upload in an AJAX action, used to plant web shells. Over 100,000 blocked attempts since June according to Wordfence               | 2.0.3.2  |
| Elementor Pro                      | [CVE-2026-32475](https://www.bleepingcomputer.com/news/security/critical-elementor-pro-flaw-exploited-to-take-over-wordpress-sites/) | A file-upload validation flaw in forms with a File Upload field. Exploitation began the day 4.2.2 shipped, 19 August                             | 4.2.2    |

All three were exploited after a patch existed. The gap between a fix and an update is where sites get compromised, for plugins and core alike.

## How to check which WordPress version a site runs [#how-to-check-which-wordpress-version-a-site-runs]

You need the version to read the tables above. On a site you administer, it is in **Dashboard > Updates**. From the outside, a WordPress page usually exposes it in the `generator` meta tag or in the `ver=` query string on core scripts and stylesheets, although many sites remove both.

The free [Technology Checker](/tools/tech-checker) reads it for you. Enter the URL and it lists WordPress with the version the page exposes, whether that version is current, and the known CVEs affecting it, along with the JavaScript libraries the page loads. WordPress ships its own jQuery, so check that row too: [old jQuery copies](/en/blog/vulnerable-jquery-version) are a frequent finding on WordPress sites.

Read the result for what it is. The checker sees the version a public page exposes. It cannot see your server configuration, so for CVE-2026-87902 it tells you whether your version is affected, and the three conditions above tell you whether the bug reaches code execution on your server. If the site hides its version, the checker reports WordPress without one, and the dashboard is the place to look. The broader method is in [What technology is this website using](/en/blog/what-technology-is-this-website-using).

## Get alerted when the next one lands [#get-alerted-when-the-next-one-lands]

A check answers for today. WordPress shipped core security releases in March, July, August and September 2026, and two of the plugin flaws above were exploited from the day of the fix, so the useful question is how fast you learn that a version you run became vulnerable.

CentralCSP builds an inventory of the scripts your visitors' browsers actually run, on every page, and maps them to technologies and versions. When a new CVE affects a version in that inventory, an alert fires with the version and the advisory. The [Technologies feature](/en/docs/platform/features/technologies) shows each library with its status and where it loads, the [supply-chain page](/platform/supply-chain) has the tour, and [Build a script inventory with CSP hash reporting](/en/blog/script-inventory) explains how the inventory is built. [Start free with CentralCSP](/register) to see your own sites.

## FAQ [#faq]

### Is WordPress 7.1.1 vulnerable? [#is-wordpress-711-vulnerable]

Yes. WordPress 7.1.1 is affected by CVE-2026-87902, the unauthenticated page-template path traversal fixed in 7.1.2 on 22 September 2026. CISA lists it as exploited in the wild. Update to 7.1.2, or to the fixed release of your branch, such as 7.0.6 or 6.9.9.

### Which WordPress versions are affected by CVE-2026-87902? [#which-wordpress-versions-are-affected-by-cve-2026-87902]

Every release from 4.7.0 to 7.1.1, except the fixed releases published on 22 September 2026 for each branch (7.0.6, 6.9.9, 6.8.10 and down to 4.7.37). WordPress 4.6 and older are unsupported and get no fix.

### Does WordPress update itself for security fixes? [#does-wordpress-update-itself-for-security-fixes]

By default, WordPress installs minor releases such as 7.1.2 automatically through background updates. A host, a plugin, or a constant in `wp-config.php` can turn that off, so confirm the version in Dashboard > Updates rather than assuming the update ran.

### What is wp2shell? [#what-is-wp2shell]

wp2shell is the name given to two WordPress core flaws fixed on 17 July 2026, CVE-2026-63030 and CVE-2026-60137. Chained, they let an unauthenticated attacker reach the database and run code on WordPress 6.9.0 to 6.9.4 and 7.0.0 to 7.0.1. WordPress forced the 7.0.2 and 6.9.5 updates through auto-updates, and CISA added CVE-2026-63030 to its exploited catalog on 21 July.

### How can I check the WordPress version of a site I do not manage? [#how-can-i-check-the-wordpress-version-of-a-site-i-do-not-manage]

Look for the `generator` meta tag or the `ver=` parameter on core assets, or enter the URL in the [Technology Checker](/tools/tech-checker), which reports the version the page exposes with its known CVEs. Only check sites you own or are authorised to assess.

## Related [#related]

* [Which jQuery versions are vulnerable, and how to find the copy your site loads](/en/blog/vulnerable-jquery-version)
* [How to detect vulnerable JavaScript libraries on a live website](/en/blog/detect-vulnerable-javascript-libraries)
* [What technology is this website using, and is any of it outdated](/en/blog/what-technology-is-this-website-using)
* [Build a script inventory with CSP hash reporting](/en/blog/script-inventory)

## Sources [#sources]

* [WordPress.org, Version 7.1.2](https://wordpress.org/documentation/wordpress-version/version-7-1-2/)
* [WordPress.org, Version 7.1.1](https://wordpress.org/documentation/wordpress-version/version-7-1-1/)
* [WordPress.org, Version 7.0.4](https://wordpress.org/documentation/wordpress-version/version-7-0-4/)
* [WordPress.org, Version 7.0.3](https://wordpress.org/documentation/wordpress-version/version-7-0-3/)
* [WordPress.org, WordPress 7.0.2 release](https://wordpress.org/news/2026/07/wordpress-7-0-2-release/)
* [WordPress.org, Version 6.9.4](https://wordpress.org/documentation/wordpress-version/version-6-9-4/)
* [CISA, CISA adds one known exploited vulnerability to catalog, 25 September 2026](https://www.cisa.gov/news-events/alerts/2026/09/25/cisa-adds-one-known-exploited-vulnerability-catalog)
* [Patchstack, WordPress 7.1.2 security release, unauthenticated LFI to RCE](https://patchstack.com/articles/wordpress-7-1-2-security-release-unauthenticated-lfi-to-rce/)
* [The Hacker News, attackers exploit WordPress CVE-2026-87902 within hours](https://thehackernews.com/2026/09/attackers-exploit-wordpress-cve-2026.html)
* [Wiz, wp2shell](https://www.wiz.io/blog/wp2shell-cve-2026-63030-cve-2026-60137)
* [CrowdSec, CVE-2026-63030 under active exploitation](https://www.crowdsec.net/vulntracking-report/cve-2026-63030-wordpress-wp2shell-sqli-to-rce)
* [SentinelOne, CVE-2026-64638](https://www.sentinelone.com/vulnerability-database/cve-2026-64638/)
* [Infosecurity Magazine, Everest Forms Pro RCE actively exploited](https://www.infosecurity-magazine.com/news/everest-forms-pro-rce-actively/)
* [The Hacker News, WooCommerce Wholesale Lead Capture flaw exploited](https://thehackernews.com/2026/09/attackers-exploit-woocommerce-wholesale.html)
* [BleepingComputer, critical Elementor Pro flaw exploited](https://www.bleepingcomputer.com/news/security/critical-elementor-pro-flaw-exploited-to-take-over-wordpress-sites/)
