WordPress security advisory (AV26-952)
WordPress before 7.1.2 is under active attack via CVE-2026-87902, an unauthenticated path traversal that can yield remote code execution.
The Canadian Centre for Cyber Security issued advisory AV26-952 on September 23, 2026, for WordPress versions before 7.1.2. CVE-2026-87902 is an unauthenticated path traversal in page-template resolution that can lead to conditional remote code execution. Open-source reporting indicates the vulnerability is being exploited in the wild. The centre urges administrators to review the linked WordPress materials and apply updates.
- CVE-2026-87902 affects WordPress versions before 7.1.2.
- Unauthenticated path traversal in template resolution can yield conditional RCE.
- Open-source reporting says the flaw is being exploited.
- The Canadian Cyber Centre urges administrators to update.
Vulnerabilities mentionedAll →
- CVE-2026-879028.118%Unauthenticated Local File Inclusion to RCE in WordPress Core (fixed in 7.1.2)published · WordPress (WordPress.org) WordPress core KEV PoC ×16
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
Full article75 words · extracted from cyber.gc.ca · click to collapse
Serial number: AV26-952
Date: September 23, 2026
As of September 22, 2026, WordPress is affected by a vulnerability in the following product:
- WordPress
- Prior to 7.1.2
Open-source reporting indicates that CVE-2026-87902 is being exploited in the wild.
The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyber.gc.ca/en/alerts-advisories/wordpress-security-advisory-av26-952