← Back to feed
Vulnerabilities & PatchesEmerging1 sourceSep 25, 2026 · 15:23via Kaspersky Blog

CVE-2026-87902: Critical Vulnerability in WordPress

Brief

A critical vulnerability has been discovered in the popular WordPress content management system that allows attackers to execute arbitrary code on the web server. The vulnerability has been assigned the number CVE-2026-87902. The good news is that on September 22, WordPress released an update that patches it.

The bad news is that the first attempts to exploit CVE-2026-87902 were detected just a few hours after the patch was released. Therefore, all companies whose corporate websites or blogs run on this platform are advised to update immediately.

WordPress versions affected by CVE-2026-87902

According to data published by WordPress on GitHub, all versions of the CMS from 4.

  • 0 through 7.
  • 1 are vulnerable. The company has released updates for all supported branches of the system; a complete table listing the patched version numbers can be found on the company’s GitHub page .
Read more on Kaspersky Blog→