Skip to content

CVE-2026-87902 explained: what the WordPress Core flaw means for your business

By Donovan Brown
September 27, 2026
8 sections
CVE-2026-87902 explained: what the WordPress Core flaw means for your business — Cyber Security article cover card from LayerLogix, with a warning alert icon
01

Introduction

CVE-2026-87902 is a flaw in WordPress Core, the software that runs a large share of business websites. It is already listed on the CISA Known Exploited Vulnerabilities (KEV) catalog, which means criminals are already using it. If your business runs a WordPress site, keep reading.

02

Does this affect you?

The two-minute check

  1. Log into your WordPress dashboard, usually at yoursite.com/wp-admin.
  2. Open Dashboard, then Updates, and note the version number shown at the top.
  3. Confirm your site is reachable from the public internet, not just an internal test copy.
  4. Confirm you are actually running WordPress Core, not a different site builder that just looks similar.

When you can stop reading

If your business does not run WordPress Core at all, this record does not apply to you. If your site is private and never reachable from the open internet, your exposure is much lower. The record does not say which specific builds are affected, so if you do run WordPress, the safest move is to keep reading rather than assume you are clear.

03

How bad is it, honestly?

What the official record says

The National Vulnerability Database (NVD) scores this flaw 8.1 out of 10, rated HIGH under Common Vulnerability Scoring System (CVSS) version 3.1. The scoring detail says an attacker can reach it over the network without any login and without tricking anyone into clicking anything. It also says the attack itself is complex to pull off, which is part of why it rates high rather than critical.

The vendor advisory describes the bug as a way for WordPress Core's page-template lookup function to be tricked into loading a readable local file from outside the normal theme folders. If certain server and theme conditions line up, that file access can lead to remote code execution (RCE), meaning an attacker can get the server to run commands it should never run.

The Exploit Prediction Scoring System (EPSS) puts the chance of exploitation in the next 30 days at 18%, in the 97th percentile of all scored flaws (FIRST.org). That is a real but far from certain chance of exploitation in the next 30 days. EPSS is a forecast of attacker activity, not a measure of how severe the flaw itself is.

This record was published on 2026-09-22 and last updated 2026-09-26. It was added to the CISA KEV catalog on 2026-09-25, with a federal remediation due date of 2026-09-28 (CISA KEV catalog). There is no reported ransomware use tied to this flaw so far.

What that means for a business like yours

An attacker does not need a password or an employee click to try this. They do need the right server and theme setup, and the attack itself takes some skill to execute. If it works, the impact is serious: an attacker could read files, change your site, or take deeper control of the server. The federal due date and KEV listing tell you this is being actively probed right now, not a theoretical risk.

04

What to do about it, step by step

If someone else manages your IT

Send them a short message like this. Keep it simple and ask for confirmation back.

  • "Are any of our WordPress sites affected by CVE-2026-87902?"
  • "Please confirm what mitigations you have put in place."
  • "Please tell me when a vendor fix is available and applied."

If you manage it yourself

  1. Open your WordPress dashboard and check the Updates screen for a new Core release.
  2. Read the vendor advisory for the current guidance, since the record does not name a fixed version yet.
  3. Review which theme you are running, since the advisory says the active theme matters to whether this bug can be triggered.
  4. Check your hosting control panel for any web application firewall settings and confirm they are turned on.
  5. Look at your server's PHP error log for unusual file-access attempts around template files.
05

How long you have

This flaw is already on the CISA KEV catalog, and the federal due date was 2026-09-28. In plain terms: now. Attackers are already probing sites for this weakness (Patchstack), so waiting does not buy you safety.

06

How to check it actually worked

There is no vendor fix listed on the record yet, so there is no update to install and confirm. Instead, check that your mitigations are actually active. Reload your site and confirm your firewall or hosting security tool shows as running, not paused. Check your PHP error log again after a day to see whether suspicious requests have stopped or continued. When the vendor does publish a fixed version, confirm the Updates screen shows that exact version number, not just "up to date."

07

What to do if you can't patch right now

Since no fix exists yet, focus on reducing what an attacker can reach. Restrict file permissions on your server so PHP processes cannot read files outside the web root. This limits how far the local-file trick can reach, though it does not close the underlying bug. Turn on or tighten a web application firewall rule set if your host offers one; this can block many exploit attempts but will not catch every variation. Limit who can log into your WordPress admin area, and use multi-factor authentication (MFA) for every account that can. None of these steps replace a vendor fix, but together they shrink your exposure while you wait for one. A broader review of your setup, through a service like our cybersecurity services, can help confirm these controls are actually working.

08

Frequently Asked Questions

Do I have to do anything if I only use WordPress for a personal blog?

The risk is lower if your blog holds no business data and is not linked to other systems, but the underlying flaw does not care what the site is used for. If it is reachable from the internet, it is still worth the two-minute check above.

Will fixing this break anything on my site?

The record does not name a fixed version yet, so there is nothing to install today. When a fix does appear, the vendor advisory is the place to check compatibility notes before applying it.

Does this affect our WordPress site if it sits behind a login wall?

The scoring detail shows this bug needs no login to attempt, so a public login page alone does not block it. Restricting network access to the admin area helps more than a login wall by itself.

How do I know if my hosting company already handled this?

Ask directly. A short email asking whether they have reviewed CVE-2026-87902 for your account, and what mitigations are in place, is a reasonable request of any host.

We handle client data — does this change our compliance obligations?

If you handle health data or financial data, an active, exploited flaw like this is exactly the kind of risk your HIPAA or FTC Safeguards Rule obligations expect you to track and address. Documenting your review and mitigation steps now is good practice regardless of the outcome.

LayerLogix offers 20+ Years Experience and 100% Texas-Based Support, with automated 24/7 monitoring and business-hours support with after-hours emergency response. If you want a second set of eyes on your WordPress setup, start with our free IT assessment or contact us directly.

Back to Blog
Keep Reading

Related Articles

Need Expert IT Support?

Let our team help your Houston business with enterprise-grade IT services and cybersecurity solutions.

Call NowBook a Call