Executive Summary
Facts Only
* Vulnerability CVE-2026-87902 exists in WordPress 7.0.2.
* The vulnerability involves unauthenticated path traversal in the page-template functionality.
* Exploitation leads to potential local PHP file inclusion and code execution.
* Stage 1 uses path traversal to include a local `.php` file into the template loader.
* Stage 1 leverages `pearcmd.php` as a file-write gadget by injecting data via the query string.
* Stage 2 includes the file written by Stage 1, executing the embedded PHP code with web-server privileges.
* The vulnerability stems from missing path containment in WordPress.
* Exploitation requires specific preconditions: a published page, a `page-*` theme directory, and `registerargcargv=3DOn` for the SAPI.
* The exploit uses URL-encoded paths to bypass input sanitization mechanisms.
Full Take
From the original · Exploit Database
# Exploit Title: WordPress 7.0.2 - Path Travesal # Google Dork: N/A # Date: 2026-09-22 # Exploit Author: Robert Ressl (https://ressl.ch) # Vendor Homepage: https://wordpress.org # Software Link: https://wordpress.org/download/releases/ # Version: WordPress 7.0.2 (patched in 7.1.2 and 7.0.6; backports to every = branch down to 4.7.37) # Tested on: WordPress 7.0.2 / PHP 8.3.33 (Apache module) /…Read the full story at exploit-db.com
Sentinel — Likely Synthetic
This document appears to be a detailed, technically precise description of a Proof-of-Concept (PoC) exploit rather than standard journalistic reporting.
