Attackers have weaponized a critical WordPress vulnerability within hours of its public disclosure, moving faster than most organizations can patch their systems.

CVE-2026-87902 carries a CVSS score of 9.2, indicating severe risk to WordPress installations worldwide. The flaw allows unauthenticated attackers to achieve remote code execution by exploiting the get_page_template() function. The vulnerability permits attackers to manipulate page-template resolution to include arbitrary readable local PHP files, giving them a foothold to execute malicious code on affected servers.

The rapid exploitation timeline reflects a persistent industry problem. Defenders operate on deployment schedules measured in days or weeks. Attackers operate on schedules measured in hours. Once technical details reach public channels, exploit code typically emerges within 24 to 72 hours. Active threat exploitation beginning immediately after disclosure suggests either accelerated development or pre-existing exploit code prepared during the vulnerability's pre-disclosure window.

WordPress installations number in the hundreds of millions globally. Approximately 43 percent of all websites run WordPress, making it a high-value target. A 9.2 CVSS score reflects a vulnerability that requires minimal attacker interaction and delivers direct system compromise. The unauthenticated nature removes a critical barrier. Attackers need not bypass login mechanisms or obtain valid credentials.

The get_page_template() function mishandles template resolution when processing user-supplied input. This design flaw creates a path traversal condition where attackers can direct the function to load PHP files from predictable locations on the server filesystem. By controlling which PHP file loads and executes, attackers establish command execution channels, install persistence mechanisms, exfiltrate data, or pivot laterally into connected systems.

Organizations running affected WordPress versions face immediate compromise risk. Web-facing WordPress installations become attack vectors for lateral movement into internal networks. Compromised servers can serve malware to site visitors, inject credential-stealing code, or participate in distributed denial-of-service operations targeting third parties.

The patch timeline matters critically here. WordPress security releases typically deploy through automatic update mechanisms, but administrators must enable those features. Many organizations disable automatic updates due to past conflicts with custom themes or plugins. Those deployments now face a choice between manual patching urgency and compatibility testing delays.

Security teams operating WordPress instances should prioritize immediate inventory of affected versions. CVE-2026-87902 requires confirmation of whether installed plugins or the WordPress core itself contains the vulnerable code. Websites without automatic updates enabled need immediate manual updates or temporary access restrictions through Web Application Firewall rules blocking suspicious page-template parameters.

Web hosting providers and managed WordPress services deploy patches faster than individual administrators. Organizations using third-party hosting should verify patch status directly rather than assuming automatic protection. Custom WordPress installations without automatic updates represent the highest risk category.

Threat actors demonstrated they recognize this window. The hours-to-exploitation timeline suggests active scanning for vulnerable instances already underway. Organizations delaying patches operate with the certainty that attackers are actively targeting their infrastructure right now.