ShadowTrackr

Search the CVE vulnerability database

Look up vulnerabilities by software, product or CVE number.

1 result for “CVE-2026-87902”

CVEPublishedCVSSShadowTrackr CVSSSummary
CVE:
CVE-2026-87902
Published
2026-09-22
CVSS:
8.1
ShadowTrackr CVSS:
9.2
Summary:
An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the active theme directories. If relevant pre-conditions for both the server and the active theme are met, this can lead to RCE.