Preliminary research
CVE-2026-87902: WordPress file inclusion and conditional code execution
AI-collected research leads through 6 October 2026, including bounded month-by-month reviews of selected social and community sources from January through September. Unranked, incomplete, not community-vetted, and subject to change.
Anonymous page queries preserve encoded traversal until template resolution, where late decoding allows local PHP inclusion outside theme roots. The demonstrated PEAR execution chain requires a suitable page-prefixed theme directory, readable PEAR files, web-runtime argv support and a writable destination; execution remains at PHP account privilege.
Record
- Researcher
- Robert Ressl
- Published by
- Robert Ressl
- Date
- Format
- Advisory
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Robert Ressl, first published at the original source. Preserved copies are kept so the citation survives its host.