← All posts
October 5, 2026wordpresscisa-kevrceweb-security

WordPress CVE-2026-87902 Is Being Exploited: Update Now

CISA added a critical WordPress Core file-inclusion vulnerability to its Known Exploited Vulnerabilities catalog. Here is how to patch and assess exposure safely.

CISA added CVE-2026-87902 to its Known Exploited Vulnerabilities catalog on September 25, 2026. WordPress had released fixes three days earlier and recommends updating immediately.

If you operate a WordPress site, install the patched release for your branch now. Do not wait to determine whether your server and theme meet every exploit precondition before patching.

What happened

WordPress describes CVE-2026-87902 / GHSA-7hp8-65ch-5whp as an unauthenticated path-traversal issue in page-template resolution. Under specific conditions involving both the server environment and active theme, an attacker can cause WordPress to include a readable local PHP file outside the active theme directories. That can lead to remote code execution.

WordPress published version 7.1.2 on September 22 with the fix and backported it to affected branches through 4.7. CISA added the vulnerability to its KEV catalog on September 25 and set September 28 as the remediation deadline for organizations subject to its directive.

Who is affected

WordPress lists all branches from 4.7 through 7.1 as affected before their corresponding security release. The patched versions are:

  • WordPress 7.1: 7.1.2
  • WordPress 7.0: 7.0.6
  • WordPress 6.9: 6.9.9
  • WordPress 6.8: 6.8.10
  • WordPress 6.7: 6.7.9
  • WordPress 6.6: 6.6.9
  • WordPress 6.5: 6.5.12
  • WordPress 6.4: 6.4.12
  • WordPress 6.3: 6.3.12
  • WordPress 6.2: 6.2.13
  • WordPress 6.1: 6.1.14
  • WordPress 6.0: 6.0.16
  • WordPress 5.9: 5.9.18
  • WordPress 5.8: 5.8.17
  • WordPress 5.7: 5.7.19
  • WordPress 5.6: 5.6.21
  • WordPress 5.5: 5.5.22
  • WordPress 5.4: 5.4.23
  • WordPress 5.3: 5.3.25
  • WordPress 5.2: 5.2.28
  • WordPress 5.1: 5.1.26
  • WordPress 5.0: 5.0.29
  • WordPress 4.9: 4.9.33
  • WordPress 4.8: 4.8.32
  • WordPress 4.7: 4.7.37

WordPress 4.6 and earlier no longer receive security updates. WordPress also cautions that only its latest version is actively supported, even though it supplied these backports.

The published exploit condition is narrower than simply running an affected version: relevant server and active-theme preconditions must also be present. Those conditions matter when assessing historical exposure, but every affected installation still needs the patch.

Was VibeScan affected?

No direct VibeScan exposure was identified. The VibeScan repository does not contain WordPress Core, PHP application code, WordPress deployment configuration, or a WordPress integration.

That conclusion applies to VibeScan itself, not to every site a customer may scan. VibeScan does not maintain an inventory of customer WordPress versions, active themes, or server environments, so customer exposure is unknown unless the site owner checks it directly.

How to check safely

From the WordPress administration dashboard, open Dashboard → Updates and record the installed version before updating. If command-line administration is part of your normal operational process, you can also inspect the version without changing it:

wp core version

Then verify all of the following:

  1. The installed WordPress version is at or above the patched release for its branch.
  2. The update completed on production, not only on a staging site.
  3. Automatic background updates did not fail or leave an older instance behind.
  4. Every independently deployed WordPress site, including old campaign and test sites, was included.

Do not send exploit payloads to production. If the site ran an affected release while internet-accessible, preserve logs and a file-integrity snapshot before making investigative changes.

Immediate mitigation and durable fix

  1. Update to WordPress 7.1.2 or the latest current WordPress release. If an immediate major upgrade is impossible, install the patched backport for the affected branch as an emergency measure.
  2. Confirm the public site and administration interface are healthy after the update.
  3. Remove or isolate abandoned WordPress installations that cannot be maintained.
  4. Review web-server, PHP, and application logs for unexpected template requests, PHP errors, or child processes during the exposed period.
  5. Compare PHP files and other executable content with a trusted backup or known-good release. Treat unexplained changes as an incident.
  6. If investigation shows code execution or credential access, isolate the host, preserve evidence, and rotate the credentials that could actually have been reached.

Updating closes the known vulnerability. It does not by itself prove that an already exposed site was never compromised.

What VibeScan detects today

VibeScan does not currently have a tested, dedicated detector for CVE-2026-87902. A normal URL scan does not establish the exact WordPress Core version, active-theme behavior, server filesystem conditions, or whether exploitation occurred. WordPress Core also is not normally represented in a JavaScript lockfile, so a Node dependency scan is not a substitute for checking the WordPress installation itself.

Use the WordPress dashboard, WP-CLI, hosting inventory, and file-integrity monitoring to verify this issue. We will not label a site affected or safe based only on a public version hint.

Primary sources

Last reviewed: October 5, 2026.

Check your own app

Free scan — no GitHub access needed. Takes 30 seconds.

Scan my app free