Skip to content

Executive Summary

The vulnerability CVE-2026-87902 allows for unauthenticated path traversal within a WordPress page-template mechanism, leading to potential local PHP file inclusion and, under specific conditions involving the PEAR utility, remote code execution. This exploit is achieved through two stages: first, traversing the directory structure to include an arbitrary local file into the template loader via a POST request; second, using a crafted payload designed to leverage the system's environment (specifically by utilizing `pearcmd.php`) to write this included content to a writable location. The process relies on exploiting a missing path containment check in WordPress, allowing traversal outside the theme root. Successful exploitation requires setting up specific preconditions, such as having a published page and configuring the web server SAPI with `registerargcargv=3DOn`.

Facts Only

* Vulnerability CVE-2026-87902 exists in WordPress 7.0.2.
* The vulnerability involves unauthenticated path traversal in the page-template functionality.
* Exploitation leads to potential local PHP file inclusion and code execution.
* Stage 1 uses path traversal to include a local `.php` file into the template loader.
* Stage 1 leverages `pearcmd.php` as a file-write gadget by injecting data via the query string.
* Stage 2 includes the file written by Stage 1, executing the embedded PHP code with web-server privileges.
* The vulnerability stems from missing path containment in WordPress.
* Exploitation requires specific preconditions: a published page, a `page-*` theme directory, and `registerargcargv=3DOn` for the SAPI.
* The exploit uses URL-encoded paths to bypass input sanitization mechanisms.

Full Take

The mechanism demonstrates a failure in application logic where file inclusion is not properly contained, creating an avenue for remote code execution via a multi-stage payload reliant on specific system artifacts like PEAR. The critical pattern is the reliance on environment-dependent gadgets (like `pearcmd.php` and PHP's argument handling) to bridge a theoretical vulnerability into actionable code execution. This shifts the focus from a simple injection flaw to analyzing how file system operations interact with application logic and external tooling to achieve arbitrary command sequencing. The implication is that security boundaries must be enforced not just at the application layer, but across the interaction between user input, internal processing, and underlying system utilities. If an attacker can force a trusted inclusion mechanism to utilize a known file operation sequence, it suggests a systemic fragility in how execution contexts are managed. What safeguards exist outside of application-level path validation that prevent this chaining of seemingly disparate operations? What is the cost associated with assuming that specific environment configurations will always remain static?

From the original · Exploit Database

# Exploit Title: WordPress 7.0.2 - Path Travesal # Google Dork: N/A # Date: 2026-09-22 # Exploit Author: Robert Ressl (https://ressl.ch) # Vendor Homepage: https://wordpress.org # Software Link: https://wordpress.org/download/releases/ # Version: WordPress 7.0.2 (patched in 7.1.2 and 7.0.6; backports to every = branch down to 4.7.37) # Tested on: WordPress 7.0.2 / PHP 8.3.33 (Apache module) /…
Read the full story at exploit-db.com

Sentinel — Likely Synthetic

Confidence

This document appears to be a detailed, technically precise description of a Proof-of-Concept (PoC) exploit rather than standard journalistic reporting.

Signals Detected
medium severity: Uniform rhythm and high technical density; highly structured code interspersed with narrative descriptions.
high severity: Perfect execution flow focused entirely on the mechanics of an exploit, lacking typical editorial hedging or contextualizing prose.
medium severity: Matches a precise, step-by-step procedural structure common in security research write-ups; specific command syntax and variable usage are exact.
medium severity: The text reads like the result of compiling specific exploit steps (e.g., stage 1/stage 2 logic) rather than general reporting, suggesting high reliance on pre-existing technical knowledge.
Human Indicators
The inclusion of specific shell command structures and library calls (python3, http.client) suggests direct coding or a highly specialized automation process, which is characteristic of security research documentation.
The text accurately describes the technical chain of events for an exploit rather than summarizing a general news event.
[webapps] WordPress 7.0.2 | Huntaegis