ZeroDayAlert

CVE-2026-87902: WordPress Core Remote File Inclusion Vulnerability

WordPress Core contains a remote file inclusion vulnerability which could allow an unauthenticated attacker to make page-template resolution include a chosen readable local `.php` file outside the active theme directories, leading to remote code execution.

WordPress Core Added to KEV 2026-09-25 Federal due 2026-09-28 Known ransomware use

Required action — quoted from CISA

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Where this comes from. The identifier, product, dates and required action above are copied verbatim from the CISA Known Exploited Vulnerabilities catalog. The action plan below is written by an AI agent from that record and published automatically. AssurePort has not independently tested this vulnerability and makes no claim about whether any specific system is affected.

Who is affected

WordPress Core contains a remote file inclusion flaw that permits unauthenticated attackers to include arbitrary readable PHP files from outside theme directories, potentially leading to remote code execution. This affects WordPress installations accessible over HTTP or HTTPS. The record does not specify affected version ranges, patch availability, or whether this applies to single-site or multisite deployments equally.

How to check whether this touches you

  • Inventory WordPress installations across your estate, noting deployment type (self-hosted, managed hosting, or cloud-based) and whether each is internet-facing.
  • Determine if each WordPress instance is reachable from the public internet without authentication (check firewall rules, WAF policies, and whether administrative interfaces are exposed).
  • Query the WordPress version reported by each installation; version reporting alone is a signal of potential exposure, as backported security patches exist and may not change the advertised version string.
  • If you run a large fleet, prioritise instances serving production workloads or handling sensitive data for version verification first.

What to do

  1. Check the WordPress vendor's official security advisory and apply any published patches or mitigations to your instances without delay, following CISA BOD 26-04 timelines (federal deadline 2026-09-28; adjust your own deadline accordingly).
  2. If patching is not immediately possible, restrict network access to WordPress administrative functions and the affected page-template resolution logic using firewall rules or a Web Application Firewall, logging all blocked attempts.
  3. Enable and centrally collect WordPress application logs and web server logs (Apache/Nginx access and error logs) covering the period from now until patching, paying attention to unusual file-inclusion patterns or references to PHP files outside theme directories.
  4. For cloud-hosted instances, verify with your hosting provider whether patches are available or whether discontinuation of the product is required under BOD 26-04; document the response.
  5. Escalate to your security or incident response team if you cannot patch within your organisation's BOD 26-04 window, or if you discover active exploitation attempts in logs.

If you find you were exposed

Exploitation of file inclusion flaws typically predates public disclosure; search your centralised logs and WordPress audit trails for evidence of unusual file-access patterns, PHP execution from non-theme directories, or unexpected outbound connections from the affected server, looking back at least 90 days or to your log retention limit. If you find indicators of exploitation, treat the affected instance as potentially compromised and escalate to incident response for forensic analysis and remediation.

Get these the morning they land.

One email, only when a vulnerability is newly confirmed as exploited — the CISA record plus our action plan. No more than one a day, and nothing on quiet days.

Knowing it exists is not the same as knowing you are exposed.

This page can tell you that CVE-2026-87902 is being exploited. It cannot tell you whether Core is running somewhere of yours that is reachable. That question is what a scan answers.

Check your own surface →