Home › Intelligence › Brief
VULNERABILITY BRIEF🔴 Critical Vulnerability

Critical WordPress RCE Vulnerability (CVE-2026-87902) Exploited Within Hours of Disclosure

Attackers are exploiting CVE‑2026‑87902, a critical unauthenticated remote code execution flaw in WordPress, within hours of its public disclosure. The bug lets threat actors include arbitrary local PHP files via the get_page_template() function, forcing immediate patching and evidence of remediation for audit readiness.

LiveThreat™ Intelligence · 📅 September 25, 2026· 📰 thehackernews.com
🔴
Severity
Critical
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
2 sector(s)
✅
Actions
4 recommended
📰
Source
thehackernews.com

Critical WordPress Remote Code Execution Vulnerability (CVE‑2026‑87902) Exploited Within Hours of Disclosure

What It Is — WordPress disclosed a critical flaw (CVE‑2026‑87902) that permits an unauthenticated attacker to achieve remote code execution by abusing the get_page_template() function to include an arbitrary readable local PHP file.

Exploitability — The vulnerability carries a CVSS 9.2 (Critical) score and is already being weaponised in the wild within hours of public disclosure; proof‑of‑concept code is publicly available.

Affected Products — All supported versions of the WordPress content management system (core) are vulnerable until patched.

Why It Matters for Trust & Control Assurance

  • Demonstrates the need for continuous, automated vulnerability‑scanning to capture high‑severity gaps the moment they appear.
  • Provides audit‑ready evidence that patch‑management controls are exercised promptly, a key trust signal for regulators and enterprise buyers.
  • Highlights the importance of mapping vulnerability‑remediation processes to a unified control spine (VCF) so a single control can satisfy multiple frameworks (e.g., NIST CSF, ISO 27001).

Recommended Actions

  • Deploy the official WordPress security update that resolves CVE‑2026‑87902 immediately across all environments.
  • Verify patch rollout with configuration‑management tooling and capture immutable evidence of remediation.
  • Integrate the finding into your continuous control‑monitoring platform to map the vulnerability‑management control to the Verisq Common Framework.
  • Review file‑inclusion settings and restrict PHP file access to mitigate future abuse.

Source: The Hacker News

📰 Original Source
https://thehackernews.com/2026/09/attackers-exploit-wordpress-cve-2026.html ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Answer one control objective. Answer ten frameworks.

The Verisq Common Framework is a spine of 84 control objectives that SOC 2, ISO 27001, NIST CSF, CMMC, HIPAA, PCI DSS, HITRUST, GDPR, ISO 42001 and NIST AI RMF map onto — each graded honestly. Satisfy an objective once and every framework that recognizes it lights up at its real strength.

See how the Verisq Common Framework works →