CVE-2026-87902CISA KEVEPSS p98.8%
CVE-2026-87902WordPress Core Remote File Inclusion Vulnerability
WordPress / Core
Description
WordPress Core contains a remote file inclusion vulnerability which could allow an unauthenticated attacker to make page-template resolution include a chosen readable local `.php` file outside the active theme directories, leading to remote code execution.
Scoring
| CVSS | 8.1 () |
| Vector | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 46.12% probability of exploitation · percentile 98.8% · 2026-10-05T12:00:23Z |
| Last modified | 2026-09-28 |
CISA KEV entry
Added to KEV: 2026-09-25