Critical 9.2
CVE-2026-87902
Active In-The-Wild Probing of WordPress Core CVE-2026-87902 Vulnerability
Vendor / product: WordPress Core
Event date: 2026-09-22
Public PoC: Yes
First tracked by RiskWire: 2026-09-23
Sources & citations (7)
- Critical WordPress Core Vulnerability Lets Attackers Execute Code Without Logging In cybersecuritynews.com · 2026-09-23
- CVE-2026-87902: Attackers Started Probing WordPress Sites Hours After the Patch patchstack.com · 2026-09-22
- Another security update for WordPress shortly heise.de · 2026-09-22
- Security Alert: WordPress Local File Inclusion to Remote Code Execution Vulnerability (CVE-2026-87902) itsc.cuhk.edu.hk · 2026-09-23
- WordPress Issues Patch for Critical Flaw That Can Enable Code Execution on Some Servers thehackernews.com · 2026-09-22
- WordPress 7.1.2 Security Release: Unauthenticated LFI to RCE patchstack.com · 2026-09-22
- CVE-2026-87902: how close is your WordPress to remote code execution? securityaffairs.com · 2026-09-23
References
See CVE-2026-87902 in context
RiskWire tracks every exploited CVE this week, cross-referenced against CISA KEV with federal remediation deadlines. Filtered to your vendor stack.
Book a 20-min demo →