# WordPress patches unauthenticated LFI flaw

Published: 2026-09-23 · Severity: routine · Sectors: technology
Canonical: https://vorant.io/reports/935b2eeb-1eea-5224-987b-05a476c05225/wordpress-patches-unauthenticated-lfi-flaw

> A WordPress vulnerability allows unauthenticated local file inclusion that can lead to remote code execution under certain configurations; patched in 7.1.2.

NCSC-NL published an advisory for CVE-2026-87902, a PHP Remote File Inclusion class vulnerability (improper control of filename for include/require statements) affecting WordPress. The flaw allows an unauthenticated attacker to force WordPress to load a local PHP file outside the active theme directories. Depending on the active theme and server configuration, this can escalate to arbitrary code execution on the server, potentially giving an attacker access to sensitive data, the ability to modify content, or further control over the affected WordPress installation.

WordPress has resolved the issue in version 7.1.2, with the security update also backported to supported older versions. The CVSS v3 score is 8.1, reflecting the significant impact despite conditional exploitability. Defenders running WordPress should prioritize upgrading to a patched version as soon as possible, particularly given the unauthenticated attack vector. No in-the-wild exploitation is mentioned in the advisory.

## Mentioned in this report

- Vulnerabilities: CVE-2026-87902

Source reporting: https://advisories.ncsc.nl/2026/ncsc-2026-0389.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/935b2eeb-1eea-5224-987b-05a476c05225/wordpress-patches-unauthenticated-lfi-flaw.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
