WordPress Remote Code Execution Vulnerability

Imported from official source

Announcement

A vulnerability was identified in identified in WordPress. A remote attacker could exploit this vulnerability to trigger remote code execution on the targeted system.

A proof-of-concept exploit have been published for CVE-2026-87902 and it is being exploited in the wild. If the active child or parent theme contains a top-level directory whose name starts with "page-", and a chosen local .php target file exists on the server and is readable by the web server account, then a remote attacker could exploit this vulnerability to trigger remote code execution. Hence, the risk level is rated as High Risk.

[Updated on 2026-09-28]
Updated Risk Level, Description, Source and Related Links.

Before installation of the software, please visit the vendor web-site for more details.

Microsoft Monthly Security Update (August 2026)

This is an extract. The publication continues at the source.

Read the original at the source: https://www.hkcert.org/security-bulletin/wordpress-remote-code-execution-vulnerability_20260924

Officially imported this from Hong Kong Computer Emergency Response Team Coordination Centre’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.

Provenance

Organization
Hong Kong Computer Emergency Response Team Coordination Centre — imported from official source
Official source
https://www.hkcert.org/getrss/security-bulletin RSS
Imported
October 03, 2026 20:41
Versions
1 recorded
Identity
https://www.hkcert.org/security-bulletin/wordpress-remote-code-execution-vulnerability_...

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.