WRITEUP · PLATFORM · WORDPRESS · CVE-2026-87902 · @YNSMROZTAS

WPSniper — include class, not a kit

● liveclk --:--:--v1.3 · detect-only

WordPress get_page_template() can include a readable local .php outside the active theme. WPSniper fingerprints the site, picks a published page, and only prints VULN when a strong PEAR banner is unique to the probe body.

wp // sniperobserve
radar--:--:--
CVE-2026-87902WordPressLFIdetect-only
WPSniper wordmark
Operator mark. Detect-only. Authorized lab.

Summary

CVE-2026-87902 sits in page-template resolution. WordPress builds page-{$pagename}.php from a URL-derived, url-decoded query variable and locate_template() includes the result. On affected builds the path is not forced to stay inside an allowed theme directory.

A closed include needs two preconditions: a top-level theme folder whose name starts with page- (the documented page-templates/ layout), and a readable .php target for the web-server account. RCE is a possible follow-on. That follow-on is not on this page and not in the public helper.

Finder on the CVE: Robert (ressl), WordPress HackerOne. Patch window starts at 7.1.2 with backports to 4.7.37. This note is the class and the classifier.

Redacted WPSniper session
Lab still. Host is lab.wordpress.local. Probe query painted out. No write gadget.

What the operator does

WPSniper detect flow
Fingerprint → page_id → theme dir → PEAR vs baseline.
  1. Home HTML + generator + /feed/ — WordPress, version, theme slug.
  2. REST /wp-json/wp/v2/pages or page_id= in HTML — a published page so the template path actually runs.
  3. GET /wp-content/themes/{slug}/page-templates/ — 200 / 401 / 403 means the directory exists.
  4. Baseline ?page_id=N versus the include probe. Confirm is digest mismatch plus unique strong PEAR tokens.

Confirm rule

A marketing page that mentions “pearcmd” is not a hit.

weak token pearcmd already in baseline HTML     FP
unique PEAR Version: + Usage: pear + Δlen        VULN
locate_template appends .php · raw /etc/passwd is the wrong oracle

Redacted lab pass

WPSniper v1.3  CVE-2026-87902
target          https://lab.wordpress.local
generator       6.8.3
theme           twentytwelve
status          affected
page_id         2
theme dir       /wp-content/themes/twentytwelve/page-templates/ → 403

VULN            unique=['PEAR Version:','Usage: pear'] Δlen=+18420

patched         7.1.2 · 7.0.6 · 6.8.10 · backports to 4.7.37
mitsec@wordpress:

What this page will not do

Fix

Upgrade to 7.1.2 or the backport for the branch: 7.0.6 · 6.9.9 · 6.8.10 … down to 4.7.37. The patch requires the resolved template path to stay inside an allowed theme directory. That is the fix, not a WAF rule.

Repo

WPSniper stays on GitHub. Classifier model. Written scope. Own lab.

Open github.com/ynsmroztas/WPSniper →

YUNUS EMRE ÖZTAŞ · MITSEC · AUTHORIZED TESTING ONLY