Critical Analysis: CVE-2026-87902 - WordPress Core Remote File Inclusion Vulnerability... — September 28, 2026
Published 28 Sep 2026 · vulnerability management, CVE analysis, threat intelligence, security operations, cybersecurity news
Initial Discovery and Context Just yesterday, September 28, 2026, the cybersecurity community received news of a critical vulnerability impacting WordPress Core, identified as CVE-2026-87902. This Remote File Inclusion (RFI) flaw, primarily affecting versions 6.0 through 6.6, carries a CVSSv3.1 score that I’d conservatively estimate in the high 9.x range, given its potential for unauthenticated RCE under specific, albeit not uncommon, configurations. The discovery surfaced from an independent researcher specializing in PHP application security, who identified the weak input sanitization during an extensive audit of WordPress’s core media handling functions. This isn't some niche plugin issue; we're talking about a fundamental problem in how WordPress processes external file references, impacting hundreds of millions of websites globally. The implications here are far-reaching, from small