PSA: Critical Unauthenticated Path Traversal Vulnerability Patched in WordPress Core
A high-severity security advisory was published regarding WordPress Core.
Tracked as CVE-2026-87902 with a CVSS severity score of N/A/10.
Executive Threat Summary
WordPress has released security updates for a critical unauthenticated path traversal vulnerability that can lead to local PHP file inclusion and, on affected server and theme configurations, remote code execution. Site owners should update WordPress Core immediately.
The post PSA: Critical Unauthenticated Path Traversal Vulnerability Patched in WordPress Core appeared first on Wordfence.
This security vulnerability presents a direct risk of unauthorized data access, arbitrary script injection, or remote site compromise if left unaddressed. Because threat actors scan the internet automatically within hours of vulnerability disclosures, affected sites must be audited immediately.
Action Plan for Website Owners
- Check Your Installed Version: Verify what version of WordPress Core is running in your WordPress admin dashboard (Plugins → Installed Plugins).
- Apply Patches Immediately: If a newer release is available, backup your database and update the software without delay.
- Inspect for Indicators of Attack: If your site cannot be updated immediately, check for unexpected administrative accounts or unusual traffic spikes.
- Get an Infrastructure Audit: Submit a rescue or security inquiry with Delvok. We verify server integrity and migrate your site to an isolated container environment.