CVE Tools
Back to feed
Exploited in the wild WordPress Core rce WordPress web-app

CVE-2026-87902: Attackers Started Probing WordPress Sites Hours After the Patch

Patchstack·By Dave Jong··6 min read
CVE Tools coverage

Patchstack observed active probing for CVE-2026-87902 less than five hours after WordPress 7.1.2 was released. The unauthenticated path traversal flaw affects WordPress Core 4.7.0 to 7.1.1 and can lead to local file inclusion and, under certain server conditions, RCE; administrators should update to 7.1.2, 7.0.6, 6.9.9, 6.8.10, or the applicable backport through 4.7.37.

Earlier today we wrote up CVE-2026-87902, the unauthenticated local file inclusion in WordPress page template resolution fixed in 7.1.2. That post covered the sink, the preconditions and the fix. This is the follow-up, because the issue was already being probed in the wild before the day was over.

Patchstack customers are protected by a RapidMitigate rule. If you have not updated yet, WordPress 7.1.2 or the patched release on your branch remains the fix.…

Continue reading on Patchstack

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store