WordPress Core flaw CVE-2026-87902 faces active exploitation
Singapore's cyber agency warns of active exploitation; WordPress has fixed the conditional path-traversal flaw in 7.1.2 and affected older branches.
Singapore's Cyber Security Agency warned on September 24 that CVE-2026-87902 in WordPress Core is being actively exploited. Patchstack separately reported probes and later attempts to write PHP files. The unauthenticated page-template path-traversal flaw can include a local PHP file and, under specific theme and server conditions, lead to remote code execution. That does not mean every WordPress site is exploitable or that every attempted attack succeeded. WordPress fixed the issue in version 7.1.2 and released patches for affected older branches. Site owners should update to the fixed release for their branch.