VORANT. Threat Intelligence Sign in Get the full feed

WordPress patches unauthenticated LFI flaw

routine vulnerability technology

A WordPress vulnerability allows unauthenticated local file inclusion that can lead to remote code execution under certain configurations; patched in 7.1.2.

NCSC-NL published an advisory for CVE-2026-87902, a PHP Remote File Inclusion class vulnerability (improper control of filename for include/require statements) affecting WordPress. The flaw allows an unauthenticated attacker to force WordPress to load a local PHP file outside the active theme directories. Depending on the active theme and server configuration, this can escalate to arbitrary code execution on the server, potentially giving an attacker access to sensitive data, the ability to modify content, or further control over the affected WordPress installation.

WordPress has resolved the issue in version 7.1.2, with the security update also backported to supported older versions. The CVSS v3 score is 8.1, reflecting the significant impact despite conditional exploitability. Defenders running WordPress should prioritize upgrading to a patched version as soon as possible, particularly given the unauthenticated attack vector. No in-the-wild exploitation is mentioned in the advisory.

Mentioned in this report

Vulnerabilities CVE-2026-87902

Source reporting: https://advisories.ncsc.nl/2026/ncsc-2026-0389.html

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free