Podatności / CISA KEV · AKTYWNIE WYKORZYSTYWANE · CVSS 8.1
CVE-2026-87902 · WordPress Core Remote File Inclusion Vulnerability
- Identyfikator
- CVE-2026-87902
- CVSS
- 8.1 HIGH
- CISA KEV
- AKTYWNIE WYKORZYSTYWANE
- Producent
- WordPress
- Produkt
- Core
- Dodano do KEV
- 2026-09-25
- Termin CISA
- 2026-09-28
WordPress Core contains a remote file inclusion vulnerability which could allow an unauthenticated attacker to make page-template resolution include a chosen readable local `.php` file outside the active theme directories, leading to remote code execution.