Sigma Watch is free and independent. If it saves you time, keep it running. ☕ Buy me a coffee
SigmaWatch
CVE coverage

CVE-2026-87902

CVSS 8.1 Actively exploited (KEV) no coverage
View on NVD →
An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the active theme directories. If relevant pre-conditions for both the server and the active theme are met, this can lead to RCE.

Detection rules

No detection found — yet
None of Sigma, Elastic, Splunk ESCU, YARA, Microsoft Sentinel, Snort, or Suricata currently has a rule referencing CVE-2026-87902.

This CVE is on CISA's Known Exploited Vulnerabilities list. It is being exploited in the wild with no public detection rule — worth writing one.