WordPress: Unauthenticated Path Traversal Leading to Conditional RCE (CVE-2026-87902)
The interesting part of CVE-2026-87902 isn’t WordPress, it’s pearcmd.php. The bug is an unauthenticated path traversal in get_page_template() hitting 4.7.0 through 7.1.1 - 22 version branches - but it only reaches RCE if there’s a readable .php file on disk to point at. That file ships in the official PHP Docker images and default cPanel setups. Your base image is part of your attack surface. Patched in 7.1.2, 7.0.6, 6.9.9 and 6.8.10.