CISA Flags Critical WordPress Core Vulnerability in Federal Exploit Database
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has officially listed a high‑severity flaw in WordPress core software, CVE-2026-87902, in its Known Exploited Vulnerabilities (KEV) catalog, signaling that the defect is already being leveraged by threat actors.
With a Common Vulnerability Scoring System (CVSS) rating of 9.2, the vulnerability ranks among the most severe in the database. While the agency has not disclosed technical details, the CVE identifier indicates a weakness in the core code of WordPress, the open‑source content‑management system that powers a sizable share of the web, including many government and commercial sites.
CISA’s KEV list is a curated set of vulnerabilities that the agency has confirmed are actively exploited in the wild. Inclusion in the catalog triggers mandatory remediation requirements for U.S. federal agencies under existing procurement and security directives, and it serves as a warning bell for private sector organizations that rely on the same software.
WordPress’s popularity makes it a frequent target for attackers, who often combine core vulnerabilities with insecure plugins or themes to gain unauthorized access, install malware, or deface sites. Security experts note that a vulnerability with a CVSS score above 9 typically allows remote code execution or privilege escalation, both of which can lead to full compromise of affected servers.
In response to the listing, the WordPress development team is expected to issue a security patch, and administrators are urged to apply updates as soon as they become available. CISA advises entities to prioritize the remediation of this flaw, conduct thorough asset inventories to identify any installations of vulnerable WordPress versions, and monitor for signs of exploitation, such as unusual network traffic or unexpected file changes.
The addition of CVE-2026-87902 to the KEV catalog underscores a broader trend of heightened scrutiny on widely deployed open‑source platforms. As cyber‑threat actors continue to weaponize known software weaknesses, agencies like CISA play a crucial role in disseminating timely alerts, enabling both public and private organizations to harden their defenses before attackers can capitalize on the exposure.
Comments (0)
Be the first to comment.
Join the discussion