CVE-2026-87902: WordPress Core
WordPress Core包含一個遠端檔案包含漏洞,可以讓一個未經認證的攻擊者使頁面模板解析包含一個在活動主題目錄外選擇可讀的本地‘.php'檔案,從而導致遠端程式碼執行。
CISA (English)
WordPress Core contains a remote file inclusion vulnerability which could allow an unauthenticated attacker to make page-template resolution include a chosen readable local `.php` file outside the active theme directories, leading to remote code execution.
- 廠商
- WordPress
- 產品
- Core
- 漏洞
- WordPress Core Remote File Inclusion Vulnerability
- 加入日期
- 2026年9月25日
- CISA 修補期限(美國聯邦機關)
- 2026年9月28日
- 已知用於勒索軟體攻擊
- 未知
- 弱點(CWE)
- CWE-98
參考資料
本站僅為資訊目的整理 CISA 目錄,並非資安建議。請遵循廠商指引與官方公告。
最後更新: · 目錄版本 2026.10.02