WordPress released fixes for CVE-2026-87902, a critical unauthenticated path-traversal/local file inclusion flaw affecting WordPress versions 4.7 through 7.1. The vulnerability abuses page-template resolution via get_page_template() to include attacker-selected readable PHP files outside the active theme directory. In susceptible server and theme configurations, this can enable remote code execution. WordPress 7.1.2 fixes the issue, with patches backported across supported branches; the flaw has a CVSS 3.1 score of 8.1.
Exploitation began shortly after the patch release, with observed traffic increasing tenfold from reconnaissance into attempts to write files to vulnerable servers, including marker payloads intended to identify hosts for subsequent operations. CISA reportedly added the vulnerability to its Known Exploited Vulnerabilities catalog on September 25. Administrators should apply the relevant WordPress update immediately; where remediation is delayed, restrict access and deploy compensating WAF controls. Teams should also review logs and the /tmp/ directory for suspicious files or activity that may predate patching.

See which actors are running it and whether you're in range.
5 events from the most recent confirmed update back to the earliest known activity.
WordPress released version 7.1.2 on September 22, 2026, to fix CVE-2026-87902, a critical unauthenticated path-traversal/local-file-inclusion flaw. Fixes were also made available for maintained branches, while releases from 4.7 onward were affected.
Patchstack observed exploitation traffic rise tenfold within days of the patch release. The activity progressed from reconnaissance to writing files and marker payloads to targeted servers, apparently to identify hosts for later operations.
CSIRT Panama issued a public notice for CVE-2026-87902, assigning it a CVSS 3.1 score of 8.1 and advising organizations to patch, enable automatic updates, and investigate systems for pre-remediation compromise indicators.
CISA added the actively exploited WordPress Core vulnerability CVE-2026-87902 to the Known Exploited Vulnerabilities catalog.
Exploitation was observed within hours of the WordPress patch publication. Attackers used page-template manipulation to target vulnerable installations, with remote code execution possible in certain server and theme configurations.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
2 references tracked. Mallory keeps watching after this page renders.
cert.ug
Open sourcecert.pa
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.