Web Hack List

Preliminary research

CVE-2026-87902: WordPress file inclusion and conditional code execution

AI-collected research leads through 6 October 2026, including bounded month-by-month reviews of selected social and community sources from January through September. Unranked, incomplete, not community-vetted, and subject to change.

Anonymous page queries preserve encoded traversal until template resolution, where late decoding allows local PHP inclusion outside theme roots. The demonstrated PEAR execution chain requires a suitable page-prefixed theme directory, readable PEAR files, web-runtime argv support and a writable destination; execution remains at PHP account privilege.

Record

Researcher
Robert Ressl
Published by
Robert Ressl
Date
Format
Advisory

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Robert Ressl, first published at the original source. Preserved copies are kept so the citation survives its host.