Defensive self-check · CISA KEV 2026-09-25

WordPress core CVE-2026-87902: version and file self-check

CISA added CVE-2026-87902 to the Known Exploited Vulnerabilities catalog on 2026-09-25. It concerns WordPress core template lookup. This page tells you what to compare and which records to review on a site you own. It does not describe how to exploit the issue.

Check these three things

  • Core version. In wp-admin open Dashboard → Updates, or read the version in wp-includes/version.php. Compare it with the fixed release named in the WordPress advisory.
  • Theme files. Look for PHP files in the active theme that you or your developer did not add, especially files that appeared after 2026-09-25.
  • Administrator accounts. Open Users → Administrator and compare the list with the people who should have access.

What to do

Update WordPress core from wp-admin or your host's panel before you keep investigating. If the version was behind the fix, keep the site on the patched release and review the file and user lists above. Use the WordPress check for a public readme pass, then confirm the core version on the server itself.

Vendor record: CISA KEV catalog, entry CVE-2026-87902.