External risk intelligence

WordPress Core File Inclusion Leading to Remote Code Execution

CVE advisoryKnown Exploit

CVE-2026-87902

This vulnerability affects WordPress, a content management system designed to be public-facing by default. It allows for unauthenticated remote code execution via the public web interface, which is a standard deployment pattern for this product on the internet.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A security vulnerability in WordPress allows an attacker to potentially execute arbitrary code on affected systems by tricking the system into loading a malicious PHP file. While complex, if successful, this could lead to a significant compromise of the affected website. The main concern is confirming if your WordPress instances are susceptible and if they have been targeted.

  • Unauthenticated code execution risk.
  • Potential for site compromise.
  • Confirm relevance and exposure.

Attack Path

How an attacker could exploit the issue

An unauthenticated attacker can manipulate the page-template resolution to include a local PHP file, potentially leading to remote code execution if specific server and theme conditions are met.

  • No authentication required.
  • Local PHP file inclusion in template resolution.
  • Leads to remote code execution.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated attacker to execute arbitrary code on a WordPress site by manipulating how page templates are resolved. This requires specific conditions related to the server and the active theme to be met, but if successful, it could compromise the site's integrity.

  • Server-side code execution.
  • Remote inclusion of local PHP files.
  • Complete site compromise.

Operational Fix

Recommended remediation, mitigation, and detection steps

The primary responsibility for addressing this vulnerability lies with the platform or infrastructure teams managing the WordPress deployment. The initial critical step involves identifying all instances of the affected WordPress Core, verifying their network reachability, and assessing their business criticality to prioritize remediation efforts.

  • Platform/Infrastructure teams own remediation.
  • Verify affected WordPress Core instances.
  • Plan remediation based on exposure risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is WordPress and how does it function?

WordPress is a widely used content management system that powers websites by organizing content through themes and templates. It uses server-side PHP files to dynamically generate the pages visitors see. Because it is designed to be public-facing, it relies on these template systems to quickly assemble site layouts, which is the specific area affected by CVE-2026-87902.

What does CWE-98 mean in the context of this CVE?

CWE-98 refers to 'Improper Control of Filename for Include/Require Statement in PHP Program.' In this CVE, it means the software fails to properly restrict which files it can load when resolving page templates. An attacker can trick the system into including a local PHP file that was not intended for use, which can lead to remote code execution.

Does any file inclusion trigger this vulnerability?

No, not every file on the server can be used to trigger the bug. The vulnerability requires specific server configurations and particular active theme settings to work. It is not triggered by simply having the software installed; the attacker must be able to influence the template resolution process, and the system must be in a state that permits the inclusion of the unauthorized file.

How do I know if my site is at risk?

Halo Surface Signal notes that since WordPress is designed to be public-facing, sites are inherently at higher risk. You should check if your version of WordPress core is listed in the affected configurations. If your instance is internet-facing, it is more accessible to unauthenticated attackers, making it a higher priority for review compared to internal-only development instances.

What should I do first to address this?

Your first step is to inventory all WordPress instances in your environment to identify which are running affected versions of the core software. Once identified, prioritize these instances based on their business criticality and network exposure. After assessment, follow vendor-provided guidance to apply the necessary security updates to the WordPress core.

References