First published · Last updated
CVE-2026-87902: WordPress Core Remote File Inclusion Vulnerability
A remote file inclusion vulnerability in WordPress Core could allow an unauthenticated attacker to cause page-template resolution to include a readable local .php file outside active theme directories, potentially leading to remote code execution. The source requires stakeholders to apply vendor mitigations and follow CISA BOD 26-04 and forensics triage guidance, or discontinue use if mitigations are unavailable.
Categories: technology
Generated scores
Scores are based on the cited reporting and use a 1–10 scale. Read the methodology.
- Confidence
- 8/10
- Geographic reach
- 4/10
- Global importance
- 6/10
- Impact magnitude
- 6/10
- Positivity
- 1/10
- Urgency
- 7/10
Why it matters
The flaw can lead to remote code execution on affected systems and therefore requires mitigation per CISA guidance.

