{"id":"CVE-2026-87902","url":"https://www.cyber-defence.io/tools/cve/CVE-2026-87902","generatedAt":"2026-09-28T00:05:44.700Z","title":"WordPress Core Remote File Inclusion Vulnerability","description":"An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the active theme directories. If relevant pre-conditions for both the server and the active theme are met, this can lead to RCE.","published":"2026-09-22T17:17:28.000Z","lastModified":"2026-09-26T04:17:50.000Z","status":"Undergoing Analysis","sourceIdentifier":"support@hackerone.com","cvss":{"version":"3.1","score":8.1,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"},"cwe":["CWE-98"],"affected":[],"epss":{"score":0.18166,"percentile":0.97111,"date":"2026-09-26","history":[{"date":"2026-09-23","score":0.0042,"percentile":0.35945},{"date":"2026-09-24","score":0.02877,"percentile":0.86257},{"date":"2026-09-26","score":0.18166,"percentile":0.97111}]},"kev":{"listed":true,"dateAdded":"2026-09-25","dueDate":"2026-09-28","knownRansomwareCampaignUse":"Unknown","notes":"Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.\nhttps://github.com/WordPress/wordpress-develop/security/advisories/GHSA-7hp8-65ch-5whp ; ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-87902"},"exploits":{"count":0,"verified":false,"firstPublished":null,"source":"Exploit-DB (https://gitlab.com/exploit-database/exploitdb)","entries":[]},"verdict":{"level":"urgent","text":"Known to be exploited in the wild (CISA KEV, CISA remediation deadline 28 September 2026). Treat as an emergency change: patch or isolate now, then hunt for prior compromise."},"changes":[{"kind":"epss","label":"EPSS jump","at":"2026-09-26T00:00:00.000Z","detail":{"to":0.18166,"from":0.02877,"percentile":0.97111},"summary":"EPSS moved from 2.9% to 18.2% probability of exploitation in the next thirty days."},{"kind":"kev","label":"Added to KEV","at":"2026-09-25T00:00:00.000Z","detail":{"name":"WordPress Core Remote File Inclusion Vulnerability","vendor":"WordPress","dueDate":"2026-09-28","product":"Core","ransomware":"Unknown"},"summary":"Added to CISA KEV — known to be exploited; federal remediation due 2026-09-28."},{"kind":"new","label":"New CVE","at":"2026-09-22T17:17:28.000Z","detail":{"score":"8.1","severity":"HIGH","publishedAt":"2026-09-22T17:17:28.310Z"},"summary":"New CVE, high severity (CVSS 8.1), EPSS 18.2%."}],"references":[{"url":"https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-7hp8-65ch-5whp","source":"support@hackerone.com"},{"url":"https://patchstack.com/articles/cve-2026-87902-attackers-started-probing-wordpress-sites-hours-after-the-patch/","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-87902","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"sources":{"nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-87902","epss":"https://www.first.org/epss/","kev":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","exploitdb":"https://www.exploit-db.com/"},"licence":"CC BY 4.0 — link back to the CVE Explorer if you publish the results; upstream data remains subject to its own terms."}