Apply the latest WordPress security updates immediately. Implement web application firewall rules to block suspicious file uploads and path traversal patterns. Monitor server logs for unauthorized file creation or execution. Restrict file permissions and disable unused PHP functions.
Quick answers
What is CVE-2026-87902?
Apply the latest WordPress security updates immediately. Implement web application firewall rules to block suspicious file uploads and path traversal patterns. Monitor server logs for unauthorized file creation or execution. Restrict file permissions and disable unused PHP functions.
How severe is CVE-2026-87902?
critical, CVSS 9.8
Is CVE-2026-87902 known to be exploited?
It is not marked known-exploited in this record.
How should CVE-2026-87902 be mitigated?
Apply the latest WordPress security updates immediately. Implement web application firewall rules to block suspicious file uploads and path traversal patterns. Monitor server logs for unauthorized file creation or execution. Restrict file permissions and disable unused PHP functions.
CVSS
9.8
Vendor
Automattic
Published
Sep 30, 2026 · 08:05
Patch
Unknown / not confirmed
Affected products
WordPress
Mitigation
Apply the latest WordPress security updates immediately. Implement web application firewall rules to block suspicious file uploads and path traversal patterns. Monitor server logs for unauthorized file creation or execution. Restrict file permissions and disable unused PHP functions.
Security researchers and threat intelligence sources report that active exploitation of CVE-2026-87902 has been observed in the wild within hours of the vulnerability's public disclosure. The flaw, rated CVSS 9.2, affects WordPress core and could allow unauthenticated attackers to include arbitrary local .php files via page-template resolution, potentially leading to remote code execution. WordPress version 6.6.2 contains the fix; administrators are advised to update immediately.
Security researchers report that threat actors are actively exploiting a critical vulnerability in WordPress to achieve remote code execution. The flaw allows attackers to write arbitrary files to the server's disk, which can then be executed to run shell commands. Exploitation marks a shift from earlier probing activity to active weaponization. The vulnerability affects widely deployed WordPress installations, raising concerns about widespread compromise if not patched promptly.