Skip to content

CVE-2026-87902

CVE

Threat entity extracted from intelligence sources

Frequency
4
occurrences
First Seen
September 22, 2026
Last Seen
September 22, 2026
API
Exploited in Wild
Ransomware Use
Public Exploits
Attack Vector

Vulnerability Overview

Exploitation Activity

Exploitation Intelligence

A critical vulnerability (CVE-2026-87902) has been discovered in WordPress Core, affecting all versions up to 7.1.1. This flaw allows unauthenticated local file inclusion via the locate_template() function, potentially leading to remote code execution under specific conditions. The vulnerability ari...

WordPress has released version 7.1.2 to address a critical vulnerability (CVE-2026-87902) that allows unauthenticated attackers to execute code on certain servers by loading a PHP file from outside the theme directories. The flaw affects all versions from 4.7.0 to 7.1.1, and site owners are urged to...

Public Exploits

Checking GitHub for proof-of-concept code…