Exploited Vulnerabilities Daily
🌐 繁體中文

← 所有新增項目

CVE-2026-87902: WordPress Core

WordPress Core包含一個遠端檔案包含漏洞,可以讓一個未經認證的攻擊者使頁面模板解析包含一個在活動主題目錄外選擇可讀的本地‘.php'檔案,從而導致遠端程式碼執行。

CISA (English)

WordPress Core contains a remote file inclusion vulnerability which could allow an unauthenticated attacker to make page-template resolution include a chosen readable local `.php` file outside the active theme directories, leading to remote code execution.

廠商
WordPress
產品
Core
漏洞
WordPress Core Remote File Inclusion Vulnerability
加入日期
2026年9月25日
CISA 修補期限(美國聯邦機關)
2026年9月28日
已知用於勒索軟體攻擊
未知
弱點(CWE)
CWE-98

參考資料

本站僅為資訊目的整理 CISA 目錄,並非資安建議。請遵循廠商指引與官方公告。

最後更新: · 目錄版本 2026.10.02