CVE Tools

CVE-2026-87902: Attackers Started Probing WordPress Sites Hours After the Patch

PatchstackBy Dave Jong6 min read

Reported exploitedWordPress Core

Our summary

Patchstack observed active probing for CVE-2026-87902 less than five hours after WordPress 7.1.2 was released. The unauthenticated path traversal flaw affects WordPress Core 4.7.0 to 7.1.1 and can lead to local file inclusion and, under certain server conditions, RCE; administrators should update to 7.1.2, 7.0.6, 6.9.9, 6.8.10, or the applicable backport through 4.7.37.

Read at Patchstack

Below is the opening; the full story is at Patchstack.

From Patchstack

Earlier today we wrote up CVE-2026-87902, the unauthenticated local file inclusion in WordPress page template resolution fixed in 7.1.2. That post covered the sink, the preconditions and the fix. This is the follow-up, because the issue was already being probed in the wild before the day was over.

Patchstack customers are protected by a RapidMitigate rule. If you have not updated yet, WordPress 7.1.2 or the patched release on your branch remains the fix.…

Continue at Patchstack

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store