## Overview
CISA added CVE-2026-87902 to its Known Exploited Vulnerabilities (KEV) catalog on September 25, 2026. This addition signals a federal deadline for agencies to address the vulnerability. The urgency stems from evidence of exploitation in the wild. The vulnerability exists in WordPress Core and allows unauthenticated attackers to execute remote code.
## Technical Details
The vulnerability arises from the `get_page_template()` function. It permits attackers to include a chosen readable local `.php` file outside the active theme directories. For successful exploitation, certain pre-conditions must be met regarding the server configuration and the active theme. If these conditions align, an attacker can achieve remote code execution (RCE).
## Impact
Successful exploitation of CVE-2026-87902 can lead to severe consequences. An attacker could execute arbitrary code on the server, potentially compromising the entire WordPress instance. This could result in data breaches, site defacement, or further attacks on connected systems. Given the widespread use of WordPress, the impact could be significant across numerous sites.
## Mitigation
Defenders should prioritize updating WordPress Core to the latest version immediately. Regularly check for security updates and apply them as they become available. Additionally, review server configurations and theme settings to ensure they do not expose sensitive files. Implementing web application firewalls (WAF) can also help detect and block exploitation attempts.
CSURFACE Threat Sensor