ALPHACON BBSGość · pl
← Podatności

Podatności / CISA KEV · AKTYWNIE WYKORZYSTYWANE · CVSS 8.1

CVE-2026-87902 · WordPress Core Remote File Inclusion Vulnerability

Identyfikator
CVE-2026-87902
CVSS
8.1 HIGH
CISA KEV
AKTYWNIE WYKORZYSTYWANE
Producent
WordPress
Produkt
Core
Dodano do KEV
2026-09-25
Termin CISA
2026-09-28
WordPress Core contains a remote file inclusion vulnerability which could allow an unauthenticated attacker to make page-template resolution include a chosen readable local `.php` file outside the active theme directories, leading to remote code execution.