HIGHVulnerability
Verified
Global

CISA KEV: WordPress Core — WordPress Core Remote File Inclusion Vulnerability

·Source: CISA KEV

Updated:

Executive Summary

WordPress Core contains a remote file inclusion vulnerability which could allow an unauthenticated attacker to make page-template resolution include a chosen readable local `.php` file outside the active theme directories, leading to remote code execution.

Analysis

WordPress Core contains a remote file inclusion vulnerability which could allow an unauthenticated attacker to make page-template resolution include a chosen readable local `.php` file outside the active theme directories, leading to remote code execution. Added to CISA Known Exploited Vulnerabilities catalog on 2026-09-25. Remediation due: 2026-09-28.

Indicators of Compromise (1)

CVE (1)
CVE-2026-87902
Source Attribution

Originally published by CISA KEV on Sep 25, 2026. Verified by: CISA.

Related Threats