Exploited Vulnerabilities Daily
🌐 English

← All new entries

CVE-2026-87902: WordPress Core

WordPress Core contains a remote file inclusion vulnerability which could allow an unauthenticated attacker to make page-template resolution include a chosen readable local `.php` file outside the active theme directories, leading to remote code execution.

Vendor
WordPress
Product
Core
Vulnerability
WordPress Core Remote File Inclusion Vulnerability
Date added
Sep 25, 2026
CISA due date (U.S. federal agencies)
Sep 28, 2026
Known ransomware campaign use
Unknown
Weakness (CWE)
CWE-98

References

This site summarizes CISA's catalog for information only. It is not security advice — follow your vendor's guidance and official advisories.

Last updated: · Catalog version 2026.10.02