ZeroBreach Request early access
← All security news
critical CVE-2026-87902

WordPress core remote file inclusion under active exploit (CVE-2026-87902)

Tags: wordpress, core, rce, cisa

A remote file inclusion vulnerability in WordPress core (CVE-2026-87902) can be escalated to unauthenticated remote code execution. It is actively exploited in the wild and was added to CISA’s Known Exploited Vulnerabilities catalog on September 25, 2026.

Affected and fixed versions

Fixed releases: 7.1.2, 7.0.6, 6.9.9, 6.8.10, with backports available as far back as the 4.7 branch. If you are on anything older than the fixed release for your branch, you are exposed.

What to do right now

  1. Update immediately to the fixed release for your branch.
  2. Check for compromise before and after patching. Patching does not remove an existing backdoor. Look for:
    • Unknown administrator users
    • Rogue PHP files, including wp-pear-rce-flag.php, poc87902.php, luci_<random>.php, and zeta_<random>.php
    • Abuse of pearcmd.php
  3. Rotate salts, force password resets, and review access logs for the window before you patched.

This is exactly the class of flaw ZeroBreach’s recurring scans are built to catch: a critical core CVE, a branch-appropriate patch, and a post-patch compromise check, on a schedule, not when you remember.