💥 The flaw can allow inclusion of readable local PHP files and may lead to RCE under certain conditions.
❌ The PoC demonstrates LFI/witness behavior, not a direct RCE or reverse shell.
✅ Fixed in WordPress 7.1.2+
🔗 PoC: https://t.co/0NxHtTuFFP
#CyberSecurity#WordPress
lpe-toolkit has been updated with new LPE exploits!
New exploits added:
- RefluXFS CVE-2026-64600
- CrackArmor CVE-2026-23268
- skb_shift CVE-2026-43503
- GRO Flag Loss CVE-2026-43503
- snap-confine CVE-2026-8933
https://t.co/Uafh1WjbqV
🚨[POC] CVE-2026-87902: WordPress Core versions up to and including 7.1.1 are affected by a Local File Inclusion vulnerability in the locate_template() function.
GitHub: https://t.co/VqaHEnmKku
🚨 CRITICAL | WordPress Core — CVE-2026-87902
A PoC by @abraxas_null has been released for an unauthenticated Local File Inclusion (LFI) flaw.
🔴 CVE: CVE-2026-87902
⚠️ CVSS 4.0: 9.2 Critical
⚠️ CVSS 3.1: 8.1 High
🎯 CWE-98
��� Affected: ≤ 7.1.1