cscli appsec-rules install crowdsecurity/vpatch-CVE-2026-879021name: crowdsecurity/vpatch-CVE-2026-879022description: 'Detects WordPress core path traversal in page template resolution (CVE-2026-87902)'3rules:4 # WP sanitizes 'pagename' with sanitize_title_for_query() before get_page_template()5 # urldecodes it, so only percent-encoded dots and slashes can reach the traversal.6 # Literal '../' never survives; anything outside [%a-z0-9 _-] is dropped, so the7 # encoded octets may be split by characters WordPress strips.8 - zones:9 - ARGS10 - BODY_ARGS11 variables:12 - pagename13 transform:14 - lowercase15 match:16 type: regex17 value: '%2e[^%a-z0-9 _.-]*%2e[^%a-z0-9 _.-]*%2f'1819labels:20 type: exploit21 service: http22 confidence: 323 spoofable: 024 behavior: 'http:exploit'25 label: 'WordPress - LFI'26 classification:27 - cve.CVE-2026-8790228 - attack.T119029 - cwe.CWE-9830