high Known exploited

CVE-2026-87902

WordPress Core Remote File Inclusion Vulnerability

WordPress Core contains a remote file inclusion vulnerability which could allow an unauthenticated attacker to make page-template resolution include a chosen readable local `.php` file outside the active theme directories, leading to remote code execution.

Published
Sep 22, 2026
CVSS
8.1
Vendor
WordPress
Product
Core
CISA due date
2026-09-28
Source
merged

References

Check your website: Korisec scans for exposed services, weak TLS, missing headers, and WordPress plugin risks. Run a free scan or start a trial.

← Back to CVE Tracker · Official record: cve.org