Act
active
WordPress CVE-2026-87902 Unauthenticated RCE Exploited Within Hours
- Engineer — Act: Unauthenticated RCE in WordPress (CVSS 9.2) is being actively exploited with a public PoC; patch WordPress core to the latest fixed release immediately and audit any internet-exposed WordPress instances for signs of compromise via local file inclusion.
- SOC/IR — Act: Active exploitation is underway — hunt for anomalous unauthenticated requests to WordPress endpoints involving path traversal or unexpected PHP file inclusion patterns, and baseline your web access logs against activity starting at the hour of CVE disclosure.
- Leader — Plan: Not yet a board-level event (no KEV, low EPSS), but WordPress’s ubiquity makes this a priority for this quarter — confirm engineering has inventoried and is patching all WordPress deployments before this escalates to KEV status.
- Signals: CVE-2026-87902 — CISA KEV: not listed, EPSS 0.03, public PoC on GitHub, reported by 2 collected sources
This entry was curated and judged by AI (Claude) with automated enrichment
(CISA KEV / EPSS / public PoC). Verify against the original source before
acting. Found a bad verdict?
Report it —
confirmed errors go to the corrections log.