WordPress security advisory (AV26-952)
Imported from official source
Serial number: AV26-952Date: September 23, 2026 As of September 22, 2026, WordPress is affected by a vulnerability in the following product: WordPress Prior to 7.1.2 Open-source reporting indicates that CVE-2026-87902 is being exploited in the wild. The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Unauthenticated path traversal in page-template resolution leading to conditional RCE · Advisory · WordPress/wordpress-develop WordPress Releases
This version
- Version
- 1 of 2
- Recorded
- September 23, 2026 16:00
- Change
- Initial
- Content hash
967c3e0511398833be02aa49278300ea- All versions
- Revision history