CISA added CVE-2026-87902 to its Known Exploited Vulnerabilities (KEV) catalogue on 25 September 2026. The vulnerability affects WordPress Core and is known as the WordPress Core Remote File Inclusion Vulnerability. It allows an unauthenticated attacker to include a chosen readable local PHP file outside the active theme directories during page-template resolution, potentially enabling remote code execution.
The flaw is a remote file inclusion vulnerability in WordPress Core. An attacker can exploit it remotely without authentication by influencing page-template resolution. Successful exploitation may allow execution of code from a locally readable PHP file. The vulnerability has a CVSS score of 8.1, rated High. A patch is available through the vendor’s security advisory.
CISA’s KEV listing confirms that attackers are actively exploiting this vulnerability. The available data does not confirm use in ransomware campaigns. Federal Civilian Executive Branch (FCEB) agencies must remediate the vulnerability by 28 September 2026.
CISA requires organisations to apply mitigations in accordance with vendor instructions, while ensuring compliance with CISA’s BOD 26-04, “Prioritising Security Updates Based on Risk”, and its “Forensics Triage Requirements”. Organisations should follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. FCEB agencies are directly affected, but all organisations should review their WordPress exposure, internet-facing assets and patch status.
See the NVD entry and CISA KEV catalogue for full details.