WordPress security advisory (AV26-952) – Update 1

Canadian Centre for Cyber Security Version 2 imported change current

Imported from official source

Serial number: AV26-952Date: September 23, 2026Updated: September 25, 2026 As of September 22, 2026, WordPress is affected by a vulnerability in the following product: WordPress Prior to 7.1.2 Open-source reporting indicates that CVE-2026-87902 is being exploited in the wild. Update 1 On September 25, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-87902 to their Known Exploited Vulnerabilities (KEV) Database. The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Unauthenticated path traversal in page-template resolution leading to conditional RCE · Advisory · WordPress/wordpress-develop WordPress Releases CISA KEV: CVE-2026-87902

This version

Version
2 of 2
Recorded
September 25, 2026 21:00
Change
Imported change
Content hash
57fcd3ccfe91a23085d4ffc643213016
All versions
Revision history

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.