Vulnerability  ·  2026-09-26

KEV: WordPress Core remote file inclusion actively exploited (CVE-2026-87902)

VulnerabilityHigh impactGlobalCVE-2026-87902
CISA added WordPress-Core remote file inclusion (CVE-2026-87902) to KEV on 25 Sept 2026 with confirmed exploitation; unauthenticated RFI can become RCE on the host.
WordPress hosts thousands of AI/chatbot plugins and agent endpoints; an unauthenticated RCE in core compromises the whole site incl. any AI features and their stored data - immediate patch priority.
Unauthenticated remote file inclusion: page-template resolution can include a chosen readable local .php file outside the active theme directories, leading to remote code execution; CISA KEV addition 25 Sept 2026 confirms in-the-wild exploitation.
WordPress Core (page-template resolution RFI)
Apply WordPress Core security update (GHSA-7hp8-65ch-5whp) immediately; follow BOD 26-04 guidance.
CISA KEV catalogWordPress GHSA-7hp8-65ch-5whp
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →