CVE-2026-87902CISA KEVEPSS p98.8%

CVE-2026-87902WordPress Core Remote File Inclusion Vulnerability

WordPress / Core

Description

WordPress Core contains a remote file inclusion vulnerability which could allow an unauthenticated attacker to make page-template resolution include a chosen readable local `.php` file outside the active theme directories, leading to remote code execution.

Scoring

CVSS 8.1 ()
VectorCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS46.12% probability of exploitation · percentile 98.8% · 2026-10-05T12:00:23Z
Last modified2026-09-28

CISA KEV entry

Added to KEV: 2026-09-25

Sourced from NVD + CISA KEV + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.