⌁ CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

Attackers Exploit WordPress CVE-2026-87902 Within Hours of Disclosure

September 24, 2026

Attackers Exploit WordPress CVE-2026-87902 Within Hours of Disclosure Ravie LakshmananSep 24, 2026Vulnerability / Web Security Threat actors have begun to actively exploit a critical security flaw in WordPress within hours of public disclosure. The vulnerability in question is CVE-2026-87902 (CVSS score: 9.2), which could allow an unauthenticated attacker to obtain remote code execution (RCE). "An unauthenticated attacker can make get_page_template() page-template resolution include a chosen readable local .php file outside the active theme directories," WordPress said in an advisory released two days ago. "If relevant preconditions for both the server environment and the active theme are met, this can lead to RCE." Successful exploitation hinges on meeting the two pre-requisites – The active child or parent theme contains a top-level…

CVEs: CVE-2026-87902