CVE-2026-87902: WordPress Core
WordPress Coreには、ページテンプレートの解像度を作成するために、未認証の攻撃者を許可するリモートファイルインクルード脆弱性が含まれています。 アクティブなテーマディレクトリの外側に、選択した読み取り可能なローカル`.php`ファイル、リモートコードの実行につながります。
CISA (English)
WordPress Core contains a remote file inclusion vulnerability which could allow an unauthenticated attacker to make page-template resolution include a chosen readable local `.php` file outside the active theme directories, leading to remote code execution.
- ベンダー
- WordPress
- 製品
- Core
- 脆弱性
- WordPress Core Remote File Inclusion Vulnerability
- 追加日
- 2026/09/25
- CISA対応期限(米国連邦機関向け)
- 2026/09/28
- ランサムウェア攻撃での利用
- 不明
- 弱点(CWE)
- CWE-98
参考情報
当サイトはCISAのカタログを情報提供のために要約したもので、セキュリティ上の助言ではありません。ベンダーの案内と公式のアドバイザリーに従ってください。
最終更新: · カタログのバージョン 2026.10.02