WordPress Remote Code Execution Vulnerability
A vulnerability was identified in identified in WordPress. A remote attacker could exploit this vulnerability to trigger remote code execution on the targeted system.
A proof-of-concept exploit have been published for CVE-2026-87902 and it is being exploited in the wild. If the active child or parent theme contains a top-level directory whose name starts with "page-", and a chosen local .php target file exists on the server and is readable by the web server account, then a remote attacker could exploit this vulnerability to trigger remote code execution. Hence, the risk level is rated as High Risk.
[Updated on 2026-09-28]
Updated Risk Level, Description, Source and Related Links.
Before installation of the software, please visit the vendor web-site for more details.
Microsoft Monthly Security Update (August 2026)
This is an extract. The publication continues at the source.
Read the original at the source: https://www.hkcert.org/security-bulletin/wordpress-remote-code-execution-vulnerability_20260924
Officially imported this from Hong Kong Computer Emergency Response Team Coordination Centre’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.
Provenance
- Organization
- Hong Kong Computer Emergency Response Team Coordination Centre — imported from official source
- Official source
- https://www.hkcert.org/getrss/security-bulletin RSS
- Imported
- October 03, 2026 20:41
- Versions
- 1 recorded
- Identity
https://www.hkcert.org/security-bulletin/wordpress-remote-code-execution-vulnerability_...