Attackers Exploit WordPress CVE-2026-87902 Within Hours of Disclosure

Summary

Attackers are actively exploiting a critical WordPress vulnerability, identified as CVE-2026-87902, shortly after its public disclosure. This flaw, with a CVSS score of 9.2, allows unauthenticated attackers to achieve remote code execution by leveraging the get_page_template() function to include a local PHP file.

IFF Assessment

FOE

The active exploitation of a critical vulnerability enabling remote code execution is bad news for defenders, as it presents an immediate threat to WordPress sites.

Severity

8.1 High

Defender Context

This highlights the critical importance of timely patching for widely used software like WordPress. Defenders should prioritize applying updates for CVE-2026-87902 immediately and monitor for any signs of compromise related to this exploit.

Read Full Story →