CVE-2026-87902: WordPress Core Remote File Inclusion Vulnerability

Summary

WordPress Core has a remote file inclusion vulnerability that could allow an unauthenticated attacker to execute remote code by including a local PHP file outside of theme directories. Users are advised to apply vendor mitigations and follow CISA's guidance on prioritizing security updates.

IFF Assessment

FOE

This vulnerability allows for remote code execution, which is a significant threat to system security.

Severity

8.1 High

CISA KEV: Listed as actively exploited. Federal patch due: September 28, 2026. Known ransomware use: Unknown.

Defender Context

This critical vulnerability in WordPress Core presents a significant risk for websites running the platform. Defenders should prioritize applying patches or mitigations immediately to prevent potential exploitation, which could lead to full system compromise and ransomware attacks.

Read Full Story →