Skip to content
CISA Known Exploited Vulnerability

CVE-2026-87902 — WordPress Actively Exploited CVE

WordPress Core contains a remote file inclusion vulnerability which could allow an unauthenticated attacker to make page-template resolution include a chosen readable local `.php` file outside the act

⚠ Actively exploited (CISA KEV) WordPress 2026
CISA catalog entry
Product
Core
Vendor
WordPress
Added to KEV
2026-09-25
Remediation due
2026-09-28

CVE-2026-87902 is tracked in the CISA Known Exploited Vulnerabilities catalog. WebPulse monitors it as part of its framework security intelligence.

View CVE-2026-87902 on the NIST National Vulnerability Database →