CISA lists exploited WordPress flaw CVE-2026-87902 in KEV
CISA added actively exploited WordPress core flaw CVE-2026-87902 (CVSS 9.2) to its KEV catalog after rapid post-patch attacks.
WordPress released 7.1.2 on September 22, 2026, fixing CVE-2026-87902, a critical unauthenticated flaw in core page-template resolution scored CVSS 9.2 and disclosed by Robert Ressl. Patchstack, GBHackers, the Canadian Centre for Cyber Security, BleepingComputer, SecurityWeek, and a later Cyber Security News report describe it as path traversal or local file inclusion that reaches remote code execution only when theme and server conditions are met; The Hacker News and an earlier Cyber Security News item characterize it more directly as unauthenticated remote code execution. GBHackers calls the 9.2 score CVSS v4 and says exploitation requires a top-level theme directory starting with page- plus a readable local PHP file, while BleepingComputer says WordPress assigned the score. The flaw affects 4.7.0 through 7.1.1, with fixes in 7.1.2 and backports 7.0.6, 6.9.9, 6.8.10, and 4.7.37; BleepingComputer says releases before 4.6 will not be fixed, while Canadian advisory AV26-952 refers more broadly to versions before 7.1.2. Probing began at 17:44 UTC on September 22, under five hours after the patch, then moved within about a day to active code-execution attempts, including abuse of PEAR pearcmd.php, with later traffic more than ten times the first evening and public scanning widespread. Security Affairs reported on September 26 that CISA added the flaw to the Known Exploited Vulnerabilities catalog and directed U.S. federal agencies to remediate it by September 24, 2026.
- CVE-2026-87902 is an unauthenticated WordPress core page-template flaw scored CVSS 9.2; Patchstack, GBHackers, the Canadian Centre, BleepingComputer, and SecurityWeek call it path traversal or local file inclusion that can lead to…
- It affects WordPress 4.7.0 through 7.1.1, was fixed in 7.1.2 on September 22, 2026, and was backported in 7.0.6, 6.9.9, 6.8.10, and 4.7.37; BleepingComputer says releases before 4.6 will not be fixed, while Canadian advisory AV26-952…
- Researcher Robert Ressl disclosed the flaw. GBHackers rates 9.2 as CVSS v4 and says exploitation needs a top-level theme directory starting with page- plus a readable local PHP file; BleepingComputer says WordPress assigned the score.
- Patchstack saw the first probes at 17:44 UTC on September 22, 2026, under five hours after the patch; those requests were reconnaissance against ordinary core files, not code execution.
- By September 23 sources reported active compromises, later traffic more than ten times the first evening, and a shift to writing PHP via PEAR pearcmd.php when server and theme conditions are met; public proof-of-concept and Nuclei scanning…
- The Canadian Centre for Cyber Security issued advisory AV26-952 on September 23, 2026, citing open-source reports of in-the-wild exploitation and urging updates.
- Security Affairs reported on September 26 that CISA added CVE-2026-87902 to the Known Exploited Vulnerabilities catalog and set a U.S. federal remediation date of September 24, 2026.
Coverage timelineoldest first · each row is one article
- · 4d agoWordPress 7.1.2 Release
WordPress.org · Security· 80
WordPress 7.1.2 patches critical unauthenticated local file inclusion that can lead to remote code execution.
- · 4d agoWordPress 7.1.2 Security Release: Unauthenticated LFI to RCE
Patchstack· 78
WordPress 7.1.2 fixes unauthenticated LFI CVE-2026-87902 that can reach remote code execution.
- · 4d agoWordPress Issues Patch for Critical Flaw That Can Enable Code Execution on Some Servers
The Hacker News· 78
WordPress patched critical CVE-2026-87902 (CVSS 9.2), an unauthenticated flaw that can execute code on some servers.
Vulnerabilities in this storyAll →
- CVE-2026-879028.118%Unauthenticated Local File Inclusion to RCE in WordPress Core (fixed in 7.1.2)published · WordPress (WordPress.org) WordPress core KEV PoC ×16
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected |
|---|