CISA Known Exploited Vulnerability
CVE-2026-87902 — WordPress Actively Exploited CVE
WordPress Core contains a remote file inclusion vulnerability which could allow an unauthenticated attacker to make page-template resolution include a chosen readable local `.php` file outside the act
CISA catalog entry
Product
Core
Vendor
WordPress
Added to KEV
2026-09-25
Remediation due
2026-09-28
CVE-2026-87902 is tracked in the CISA Known Exploited Vulnerabilities catalog. WebPulse monitors it as part of its framework security intelligence.
Related vulnerabilities