Kritiska WordPress ievainojamība CVE-2026-87902

Imported from official source

Announcement

Vairākās WordPress versijās atklāta kritiska ievainojamība CVE-2026-87902 ar CVSS v4.0 vērtējumu 9,2 . Tā neautentificētam uzbrucējam ļauj panākt, ka get_page_template() funkcija lapas veidnes noteikšanas procesā iekļauj lasāmu .php failu ārpus aktīvās tēmas direktorijām.

Read the original at the source: https://cert.lv/lv/2026/09/kritiska-wordpress-ievainojamiba-cve-2026-87902

Officially imported this from CERT.LV’s own source. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.

Provenance

Organization
CERT.LV — imported from official source
Official source
https://cert.lv/lv/feed/rss/viss RSS
Imported
October 03, 2026 20:32
Versions
1 recorded
Identity
https://cert.lv/lv/2026/09/kritiska-wordpress-ievainojamiba-cve-2026-87902

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.