{"id":36823,"date":"2026-09-26T02:24:49","date_gmt":"2026-09-25T15:24:49","guid":{"rendered":"https:\/\/www.kaspersky.com.au\/blog\/cve-2026-87902-wordpress-vulnerability\/36823\/"},"modified":"2026-09-26T02:24:49","modified_gmt":"2026-09-25T15:24:49","slug":"cve-2026-87902-wordpress-vulnerability","status":"publish","type":"post","link":"https:\/\/www.kaspersky.com.au\/blog\/cve-2026-87902-wordpress-vulnerability\/36823\/","title":{"rendered":"WordPress arbitrary code execution vulnerability"},"content":{"rendered":"<p>A critical vulnerability <a href=\"https:\/\/ressl.ch\/blog\/cve-2026-87902-wordpress\/\" target=\"_blank\" rel=\"noopener nofollow\">has been discovered<\/a> in the popular WordPress content management system that allows attackers to execute arbitrary code on the web server. The vulnerability has been assigned the number CVE-2026-87902. The good news is that on September 22, WordPress <a href=\"https:\/\/wordpress.org\/news\/2026\/09\/wordpress-7-1-2-release\/\" target=\"_blank\" rel=\"noopener nofollow\">released<\/a> an update that patches it. The bad news is that the first attempts to exploit CVE-2026-87902 were <a href=\"https:\/\/thehackernews.com\/2026\/09\/attackers-exploit-wordpress-cve-2026.html\" target=\"_blank\" rel=\"noopener nofollow\">detected<\/a> just a few hours after the patch was released. Therefore, all companies whose corporate websites or blogs run on this platform are advised to update immediately.<\/p>\n<h2>WordPress versions affected by CVE-2026-87902<\/h2>\n<p>According to data published by WordPress on GitHub, all versions of the CMS from 4.7.0 through 7.1.1 are vulnerable. The company has released updates for all supported branches of the system; a complete table listing the patched version numbers can be found on <a href=\"https:\/\/github.com\/WordPress\/wordpress-develop\/security\/advisories\/GHSA-7hp8-65ch-5whp\" target=\"_blank\" rel=\"noopener nofollow\">the company\u2019s GitHub page<\/a>. The latest version of WordPress should be updated to version 7.1.2 (or newer).<\/p>\n<h2>What\u2019s the nature of the CVE-2026-87902 vulnerability, and why is it so dangerous?<\/h2>\n<p>Under normal circumstances, WordPress loads PHP template files only from a specific folder within the active theme. However, due to the CVE-2026-87902 vulnerability, an attacker can craft a request to WordPress in such a way that an arbitrary PHP file is included \u2014 without requiring any authorization. Yes, the file must already be uploaded to the targeted server in some way, but that\u2019s not really a problem for an attacker.<\/p>\n<p>It sounds like a path traversal vulnerability, but in most publications, <a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/cve-2026-87902\" target=\"_blank\" rel=\"noopener nofollow\">CVE-2026-87902<\/a> is classified as an RCE (Remote Code Execution) vulnerability because, under certain WordPress and PHP server configurations, the attack can lead to the execution of arbitrary code.<\/p>\n<h2>How to stay safe<\/h2>\n<p>The only way to secure a corporate WordPress site is to install the latest version. The researcher who discovered the vulnerability also <a href=\"https:\/\/ressl.ch\/blog\/cve-2026-87902-wordpress\/\" target=\"_blank\" rel=\"noopener nofollow\">offers<\/a> several tips for hardening CMS security, but emphasizes that these are meant to complement the patch, not replace it.<\/p>\n<p>The Hacker News <a href=\"https:\/\/thehackernews.com\/2026\/09\/attackers-exploit-wordpress-cve-2026.html\" target=\"_blank\" rel=\"noopener nofollow\">lists<\/a> several PHP filenames and IP addresses used in the attack via CVE-2026-87902. These can serve as indicators that a WordPress instance has been compromised.<\/p>\n<p>Given that only a few hours pass between the publication of information about a vulnerability\u2019s existence and the start of attacks exploiting it, it\u2019s crucial for companies to have a properly configured, centralized vulnerability management system. To achieve this, they should have a specialized solution capable of identifying and resolving vulnerabilities, prioritizing them based on actual risks, and automating remediation processes.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>CVE-2026-87902, a new critical vulnerability in the WordPress core, is already being actively exploited in real-world attacks. <\/p>\n","protected":false},"author":2698,"featured_media":36824,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1999,2993,2994],"tags":[3273,268,640,304],"class_list":["post-36823","post","type-post","status-publish","format-standard","has-post-thumbnail","category-business","category-enterprise","category-smb","tag-rce","tag-vulnerabilities","tag-vulnerability","tag-wordpress"],"hreflang":[{"hreflang":"en-au","url":"https:\/\/www.kaspersky.com.au\/blog\/cve-2026-87902-wordpress-vulnerability\/36823\/"},{"hreflang":"en-in","url":"https:\/\/www.kaspersky.co.in\/blog\/cve-2026-87902-wordpress-vulnerability\/31082\/"},{"hreflang":"en-ae","url":"https:\/\/me-en.kaspersky.com\/blog\/cve-2026-87902-wordpress-vulnerability\/26113\/"},{"hreflang":"en-gb","url":"https:\/\/www.kaspersky.co.uk\/blog\/cve-2026-87902-wordpress-vulnerability\/30915\/"},{"hreflang":"ru","url":"https:\/\/www.kaspersky.ru\/blog\/cve-2026-87902-wordpress-vulnerability\/42734\/"},{"hreflang":"x-default","url":"https:\/\/www.kaspersky.com\/blog\/cve-2026-87902-wordpress-vulnerability\/56459\/"},{"hreflang":"ru-kz","url":"https:\/\/blog.kaspersky.kz\/cve-2026-87902-wordpress-vulnerability\/31083\/"},{"hreflang":"en-za","url":"https:\/\/www.kaspersky.co.za\/blog\/cve-2026-87902-wordpress-vulnerability\/36492\/"}],"acf":[],"banners":"","maintag":{"url":"https:\/\/www.kaspersky.com.au\/blog\/tag\/vulnerability\/","name":"vulnerability"},"_links":{"self":[{"href":"https:\/\/www.kaspersky.com.au\/blog\/wp-json\/wp\/v2\/posts\/36823","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.kaspersky.com.au\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.kaspersky.com.au\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.au\/blog\/wp-json\/wp\/v2\/users\/2698"}],"replies":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.au\/blog\/wp-json\/wp\/v2\/comments?post=36823"}],"version-history":[{"count":0,"href":"https:\/\/www.kaspersky.com.au\/blog\/wp-json\/wp\/v2\/posts\/36823\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.au\/blog\/wp-json\/wp\/v2\/media\/36824"}],"wp:attachment":[{"href":"https:\/\/www.kaspersky.com.au\/blog\/wp-json\/wp\/v2\/media?parent=36823"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.kaspersky.com.au\/blog\/wp-json\/wp\/v2\/categories?post=36823"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.kaspersky.com.au\/blog\/wp-json\/wp\/v2\/tags?post=36823"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}