CISA Warns of Actively Exploited WordPress Vulnerability
CISA has added a WordPress Core Remote File Inclusion vulnerability, CVE-2026-87902, to its Known Exploited Vulnerabilities (KEV) Catalog after confirming active exploitation. Remote file inclusion flaws allow attackers to trick a website into loading malicious code from an external source, often leading to full control of the affected site or server.
WordPress powers a large share of small business websites, making this a relevant risk for Australian SMBs running WordPress sites, plugins or themes. While the KEV Catalog directive formally applies to US federal agencies, CISA encourages all organisations to treat listed vulnerabilities as high priority and patch quickly, since these are flaws known to be under active attack rather than theoretical risks.
Businesses should check whether their WordPress installations, including managed hosting platforms, are affected and apply available updates immediately. Where a patch has been delayed, organisations should also check logs for signs of prior compromise, as attackers may have already exploited the flaw before a fix was applied.