Critical WordPress Vulnerability Under Active Attack Immediately After Disclosure

Threat actors are actively exploiting a critical WordPress vulnerability, CVE-2026-87902, with a CVSS score of 9.2. The flaw allows unauthenticated attackers to achieve remote code execution by manipulating page-template resolution to include a chosen local PHP file. Exploitation began within hours of public disclosure.
The disclosure of CVE-2026-87902, a critical flaw in WordPress with a CVSS score of 9.2, has triggered immediate, active exploitation. The vulnerability enables unauthenticated remote code execution by abusing page-template resolution to load a locally chosen PHP file. Within hours of public details emerging, threat actors moved to weaponize the flaw, underscoring the speed at which known vulnerabilities are targeted. This incident highlights the persistent risk facing the vast ecosystem of sites built on WordPress, where a single unpatched component can expose entire infrastructures to compromise. The rapid exploitation timeline emphasizes the necessity for administrators to prioritize patch deployment and monitor for indicators of intrusion, as the window between disclosure and attack continues to shrink.
This vulnerability could affect millions of WordPress-powered websites, from small blogs to enterprise platforms, potentially enabling attackers to seize control, steal data, or deploy malware. Site owners and users may face data breaches, service disruptions, and reputational harm. The speed of exploitation suggests that unpatched systems are at immediate risk, and the broader cybersecurity community may see an increase in related attacks. However, the impact depends on how quickly hosting providers and administrators apply available fixes, as well as on the effectiveness of existing security layers.