Nicheloom

Market intelligence for builders — see what's gaining traction before it's crowded.

CVE-2026-87902

CVE-2026-87902 - WordPress - WordPress Core - Critical 9.2 - Unauthenticated Local File Inclusion (conditional RCE)

Details

External ID
1382116271
Source
GITHUB
Company
—
Product
CVE-2026-87902
Website domain
github.com
Launched
Sept. 22, 2026
Cohort
—
Upvotes
32
Upvotes percentile
0.7396233666410453
Tags
—
Fetched at
Sept. 26, 2026, 10:54 p.m.
Updated at
Sept. 26, 2026, 10:54 p.m.

Enrichment

Theme
security exploits and system hacking tools
Vertical
Security
Function
Dev tools
Audience
Developer
AI stance
Not AI
Project type
Hobby / open-source project
Normalized one-liner
vulnerability advisory and exploit documentation for wordpress core
Manually corrected
False

Could you build this?

No Finding and developing an unauthenticated local file inclusion (LFI) exploit yielding conditional remote code execution against WordPress core requires deep offensive security expertise and manual vulnerability research.

What it would actually take: Security researchers perform manual source code audits, dynamic taint analysis, and fuzzing of WordPress Core's request lifecycle. Exploiting LFI to RCE conditionally typically requires finding log poisoning or PHP wrapper manipulation techniques alongside precise knowledge of server environments. This requires expert-level exploit development and deep familiarity with PHP internals.

Competitors

Other products that read as similar to this one — 114 launches clear the similarity bar, closest 8 shown.

Attention rank: #29 of 115 (itself plus its competitors, highest first — normalized so YC and Product Hunt are compared fairly).

Launched 293 days after the earliest competitor.

Other launches for this product

Same idea, different domain

Nobody's really built a dev tools tool for Sales yet.