Home · Wiki · Incidents & Campaigns
type: incident · created: 2026-09-25 · updated: 2026-09-25 · tags: [incident, global] · confidence: high · severity: medium · affected_sectors: [global] · au_impact: true

WordPress patched CVE-2026-87902 (CVSS 9.2) on 22 September and attackers began exploiting it within hours, per honeypot evidence from Previdian, which observed attempts originating from 104.194.9[.]227 in New Jersey. The flaw is an unauthenticated local file inclusion in get_page_template() page-template resolution: an attacker can cause a template include to load a chosen readable local .php file from outside the active theme directories, producing remote code execution where two preconditions hold — the active parent or child theme contains a top-level directory whose name begins with page- (for example page-templates), and a target .php file exists on the server and is readable by the web server account (for example pearcmd.php). The GitHub security advisory is GHSA-7hp8-65ch-5whp. The story matters beyond the CVSS score: this is the second consecutive day the same flaw has appeared in the day's coverage, moving from "probed at ten times the initial rate" to confirmed exploitation, and WordPress's installed base of small-business and not-for-profit sites patches slowly.

Attribute Detail
Sector Global (Macro)
Date 2026-09-25
Source The Hacker News
Reliability Tier 2
CVEs CVE-2026-87902