Critical WordPress Remote Code Execution Vulnerability (CVE‑2026‑87902) Exploited Within Hours of Disclosure
What It Is — WordPress disclosed a critical flaw (CVE‑2026‑87902) that permits an unauthenticated attacker to achieve remote code execution by abusing the get_page_template() function to include an arbitrary readable local PHP file.
Exploitability — The vulnerability carries a CVSS 9.2 (Critical) score and is already being weaponised in the wild within hours of public disclosure; proof‑of‑concept code is publicly available.
Affected Products — All supported versions of the WordPress content management system (core) are vulnerable until patched.
Why It Matters for Trust & Control Assurance
- Demonstrates the need for continuous, automated vulnerability‑scanning to capture high‑severity gaps the moment they appear.
- Provides audit‑ready evidence that patch‑management controls are exercised promptly, a key trust signal for regulators and enterprise buyers.
- Highlights the importance of mapping vulnerability‑remediation processes to a unified control spine (VCF) so a single control can satisfy multiple frameworks (e.g., NIST CSF, ISO 27001).
Recommended Actions
- Deploy the official WordPress security update that resolves CVE‑2026‑87902 immediately across all environments.
- Verify patch rollout with configuration‑management tooling and capture immutable evidence of remediation.
- Integrate the finding into your continuous control‑monitoring platform to map the vulnerability‑management control to the Verisq Common Framework.
- Review file‑inclusion settings and restrict PHP file access to mitigate future abuse.
Source: The Hacker News