This article was collected and archived by Digital Sovereignty Watch from an institutional or public source relevant to digital sovereignty, technology policy, cybersecurity, cloud services, artificial intelligence or European regulation.
Cybersecurity
Critical WordPress Vulnerability CVE-2026-87902
A critical vulnerability CVE-2026-87902 with a CVSS score of 9.2 has been discovered in multiple WordPress versions. It allows an unauthenticated attacker to cause the get_page_template() function to include a readable .php file outside the active theme directories during the template loading process. The vulnerability has a publicly available PoC (proof of concept), so active exploitation in attacks is expected. Under certain conditions, this vulnerability can lead to remote code execution on the server. These conditions relate to the theme structure used and files available on the server. Additional information from the developer: https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-7hp8-65ch-5whp