What happened
CISA added WordPress-Core remote file inclusion (CVE-2026-87902) to KEV on 25 Sept 2026 with confirmed exploitation; unauthenticated RFI can become RCE on the host.
Why it matters
WordPress hosts thousands of AI/chatbot plugins and agent endpoints; an unauthenticated RCE in core compromises the whole site incl. any AI features and their stored data - immediate patch priority.
Attack vector
Unauthenticated remote file inclusion: page-template resolution can include a chosen readable local .php file outside the active theme directories, leading to remote code execution; CISA KEV addition 25 Sept 2026 confirms in-the-wild exploitation.
Affected systems
WordPress Core (page-template resolution RFI)
Mitigation
Apply WordPress Core security update (GHSA-7hp8-65ch-5whp) immediately; follow BOD 26-04 guidance.