WordPress CVE-2026-87902 Exploited Within Hours of Disclosure
Threat actors have begun actively exploiting a critical WordPress vulnerability, CVE-2026-87902 (CVSS 9.2), within hours of public disclosure. The flaw lets an unauthenticated attacker achieve remote code execution by making get_page_template() resolution include a chosen readable local .php file.
- CVE-2026-87902 carries a CVSS score of 9.2
- Exploitation began hours after public disclosure
- Unauthenticated attack leads to remote code execution
- Flaw is in get_page_template() resolution
Read next
Security