CVE-2026-87902
Gravedad CVSS v3.1:
ALTA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
22/09/2026
Última modificación:
22/09/2026
Descripción
*** Pendiente de traducción *** An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the active theme directories. If relevant pre-conditions for both the server and the active theme are met, this can lead to RCE.
Impacto
Puntuación base 3.x
8.10
Gravedad 3.x
ALTA


