#1148743 wordpress: CVE-2026-87902 Unauthenticated path traversal leading to conditional RCE

Package:
wordpress
Source:
wordpress
Submitter:
Craig Small
Date:
2026-09-28 11:59:03 UTC
Severity:
normal
Tags:
#1148743#5
Date:
2026-09-22 20:59:52 UTC
From:
To:
An unauthenticated attacker can make get_page_template() page-template
resolution include a chosen readable local .php file outside the active
theme directories. If relevant pre-conditions for both the server
environment and the active theme are met, this can lead to RCE.

7.1.2 and 6.8.10 have fixes for sid and trixie respectively.

Refs:
https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-7hp8-65ch-5whp
https://wordpress.org/news/2026/09/wordpress-7-1-2-release/

#1148743#8
Date:
2026-09-23 10:18:17 UTC
From:
To:
Hello,

Bug #1148743 in wordpress reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/debian/wordpress/-/commit/67daa424de6ad008577b6bbcee48bf9797218d64
------------------------------------------------------------------------
new upstream security release 7.1.2

Fixes: CVE-2026-87902 Conditional RCE in theme path traversal
Closes: #1148743
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1148743

#1148743#15
Date:
2026-09-23 10:34:13 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
wordpress, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1148743@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Craig Small <csmall@debian.org> (supplier of updated wordpress package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Wed, 23 Sep 2026 20:13:17 +1000
Source: wordpress
Architecture: source
Version: 7.1.2+dfsg1-1
Distribution: unstable
Urgency: high
Maintainer: Craig Small <csmall@debian.org>
Changed-By: Craig Small <csmall@debian.org>
Closes: 1148743
Changes:
 wordpress (7.1.2+dfsg1-1) unstable; urgency=high
 .
   * new upstream security release
     Fixes CVE-2026-87902 Conditional RCE in theme path traversal
     Closes: #1148743
Checksums-Sha1:
 2a69d574fd50f4ef8ac065533a5a81fecba9d812 2359 wordpress_7.1.2+dfsg1-1.dsc
 083d27fcb2fc516e15d8dd1e53100fef63083b38 28033704 wordpress_7.1.2+dfsg1.orig.tar.xz
 dd51b5d3d1f9f6def227fcdb169ca625bd920ec4 1603668 wordpress_7.1.2+dfsg1-1.debian.tar.xz
 96c52195b8bc4f44a9e6413c63841c00344caf89 7229 wordpress_7.1.2+dfsg1-1_amd64.buildinfo
Checksums-Sha256:
 32ce143b9b693606bff1f4bf7f8b54f175b38ae677ca3534770df368770c300b 2359 wordpress_7.1.2+dfsg1-1.dsc
 fb3e9f04807bb0b9e123fbf73555c6378fb715aac279359b4b2f3b7a04dfc1db 28033704 wordpress_7.1.2+dfsg1.orig.tar.xz
 dc556c4e3139b964f0eaed4734ef50300bce06178028b99fc2a58ab37822a35b 1603668 wordpress_7.1.2+dfsg1-1.debian.tar.xz
 73b55ac5727ca21eb83e923c55d88cb596153d73280501d6428847a889bc4cf1 7229 wordpress_7.1.2+dfsg1-1_amd64.buildinfo
Files:
 6b93e284b1fbbdcb8f141a746f25c25e 2359 web optional wordpress_7.1.2+dfsg1-1.dsc
 30d1cb5b0fb84e7e066fc0db88b87e5b 28033704 web optional wordpress_7.1.2+dfsg1.orig.tar.xz
 573db4e72262eecebdb9a199cf8b5e8e 1603668 web optional wordpress_7.1.2+dfsg1-1.debian.tar.xz
 ae3df408b7026ef661dc01b767a62243 7229 web optional wordpress_7.1.2+dfsg1-1_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEXT3w9TizJ8CqeneiAiFmwP88hOMFAmqzpyQACgkQAiFmwP88
hOP+7g/8Cb2bQJpT6yiOmUTpgI50HoIYBZAK7cgOY+2mekCrPLMkUXuzW6dibB90
qBYKXQvdCWeULNhGQDnXbG/uCuT0CkV8Hmd6SMHMJ6UIAwHYvnO1f/5XY82Y6TFu
H9LsmuExiCzR2eqwfLlYhmRTiYOsebGE400B/HQSo9hIpLs45YdlZNGrzYztexER
dyG9pXXTnbTSM2N9m81zGkAC4P11CwH5WO/+kbdsgQovtqsgbWYrAv8P+cUlYVjC
Wos54CFen7lLZ6+L8T/QkhbuEMJGcBC0HYO+lWcaU7HxHmw+77K/J3KGoeCD+O/P
LYYooKZNXWB333S0hSyl4WgmehwJMy3P3K7I2RtdoITsK1/vQ82ygMGFMShltynS
n+BH32rhSIDVA7Z27Ae4LuQxBhSJAdvS9Qw3npIFMoSv5950eaL5v7qZmDNyctJY
GJryDNXVR05kkaPUQXLwauI+4CTCqAfoofKzWqZ3IWvzqwl0XQ3hWylc82dPkdDo
RMI3K4MnrrVeSkoQjuuDTp8GgEgWYp1o9CwVWd7M3Tirm0PaIHVdphzgIWlC0sAg
vV8NRlTYBVr07BKO+XLeDGNNYw+cVmro4sv45kQDzYMbQdxQbyh6Fqqj8GHy4kyS
sju5uTDQBg68uRduUqewlnRPXpzh5yL5qMTpMZPhkKcJiuXVWbM=
=BTUF
-----END PGP SIGNATURE-----