CISA Adds Actively Exploited WordPress Core File-Inclusion Flaw to KEV

Security analyst reviewing a WordPress core vulnerability alert

CISA has added CVE-2026-87902, a WordPress core file-inclusion vulnerability, to its Known Exploited Vulnerabilities catalog after confirming active exploitation. The issue affects WordPress versions before 7.1.2, with fixes also backported to maintained older branches.

Specific conditions can turn local inclusion into code execution

The flaw involves page-template resolution in get_page_template(). An unauthenticated attacker can cause WordPress to include a chosen readable local PHP file outside the active theme directories. Exploitation requires additional server and theme preconditions, but a successful chain can lead to remote code execution. The CVE record assigns a high-severity score and notes that no user interaction or prior privileges are required.

WordPress released version 7.1.2 on September 22 and recommended immediate updates. CISA added the vulnerability to KEV on September 25, while public reporting documented probing shortly after the patch became available.

Inventory and verification matter after patching

Operators should confirm the actual WordPress core version on every site, apply the relevant security release, review web and file-change telemetry, and verify that unsupported instances are not exposed. Patching does not by itself prove that an already-exposed site was not accessed. SectechMedia follows related operational risks in its cybersecurity coverage.

Sources

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *