Fedora 45 : wordpress (2026-c7024b3255)

high Nessus Plugin ID 362714

Synopsis

The remote Fedora host is missing one or more security updates.

Description

The remote Fedora 45 host has a package installed that is affected by a vulnerability as referenced in the FEDORA-2026-c7024b3255 advisory.

## WordPress 7.1.2 Security Release

Security updates included in this release

- Unauthenticated path traversal in page-template resolution leading to conditional RCE
**CVE-2026-87902**

----

## WordPress 7.1.1 Maintenance and Security Release

Security updates included in this release

- Stored cross-site scripting in wpautop() allows an unauthenticated visitor to inject script (subject to comment approval), reported by Rafie Muhammad (Awesome Motive, Inc.).
- HTML API: set_modifiable_text() allows breaking out of a comment via abrupt-closing sequences, reported by Jeremy Felt of the WordPress Security Team.
- Stored XSS in some themes that support custom headers, reported by Jeremy Felt of the WordPress Security Team.
- Specially crafted URLs can automatically install and preview an inactive theme from WordPress.org, reported by Paulos Yibelo and pwn.ai.
- Site Administrator can network-activate an installed Network-only plugin, reported by Jesse McNeil.
- Authenticated Path Traversal in WP REST Templates Controller, reported by Anthropic.
- XML-RPC can be used to publish customize_changeset posts that bypass checks for edit_css, reported by Ben Bidner of the WordPress Security Team.
- Contributor+ Arbitrary Post Overwrite, reported by Anthropic.
- Missing read_post check in attachment_submitbox_metadata() leaks a private parent-post title, reported by HDWSec.
- Missing Authorization leads to Draft/Pending Post Slug Disclosure by Contributor+, reported by hermanhms.
- Comments, including notes, can be reparented by any authenticated user, reported by viridis.



Tenable has extracted the preceding description block directly from the Fedora security advisory.

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.

Solution

Update the affected wordpress package.

See Also

https://bodhi.fedoraproject.org/updates/FEDORA-2026-c7024b3255

Plugin Details

Severity: High

ID: 362714

File Name: fedora_2026-c7024b3255.nasl

Version: 1.1

Type: Local

Agent: unix

Published: 10/2/2026

Updated: 10/2/2026

Supported Sensors: Agentless Assessment, Continuous Assessment, Frictionless Assessment Agent, Nessus Agent, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

Risk Information

VPR

Risk Factor: Critical

Score: 9.4

Percentile: 99.82

CVSS v2

Risk Factor: High

Base Score: 7.6

Temporal Score: 6.6

Vector: CVSS2#AV:N/AC:H/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2026-87902

CVSS v3

Risk Factor: High

Base Score: 8.1

Temporal Score: 7.7

Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:H/RL:O/RC:C

Vulnerability Information

CPE: cpe:/o:fedoraproject:fedora:45, p-cpe:/a:fedoraproject:fedora:wordpress

Required KB Items: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 9/23/2026

Vulnerability Publication Date: 9/22/2026

CISA Known Exploited Vulnerability Due Dates: 9/28/2026

Reference Information

CVE: CVE-2026-87902

FEDORA: 2026-c7024b3255

IAVA: 2026-A-1055