CISA KEV Alert 25 Sept 2026, 20:01 UTC

CISA Warns of Actively Exploited WordPress Flaw Enabling Code Execution

CyberSIXT Evidence Panel Source marked as original reporting
Primary Source cisa.gov
CISA KEV Listed in KEV
Patch Patch Status Unknown

CISA added CVE-2026-87902 to its Known Exploited Vulnerabilities (KEV) catalogue on 25 September 2026. The vulnerability affects WordPress Core and is known as the WordPress Core Remote File Inclusion Vulnerability. It allows an unauthenticated attacker to include a chosen readable local PHP file outside the active theme directories during page-template resolution, potentially enabling remote code execution.

The flaw is a remote file inclusion vulnerability in WordPress Core. An attacker can exploit it remotely without authentication by influencing page-template resolution. Successful exploitation may allow execution of code from a locally readable PHP file. The vulnerability has a CVSS score of 8.1, rated High. A patch is available through the vendor’s security advisory.

CISA’s KEV listing confirms that attackers are actively exploiting this vulnerability. The available data does not confirm use in ransomware campaigns. Federal Civilian Executive Branch (FCEB) agencies must remediate the vulnerability by 28 September 2026.

CISA requires organisations to apply mitigations in accordance with vendor instructions, while ensuring compliance with CISA’s BOD 26-04, “Prioritising Security Updates Based on Risk”, and its “Forensics Triage Requirements”. Organisations should follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. FCEB agencies are directly affected, but all organisations should review their WordPress exposure, internet-facing assets and patch status.

See the NVD entry and CISA KEV catalogue for full details.

View CISA KEV Entry

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline