Vulnerability Analysis CVE-2026-87902 WordPress Core – PHP Template Path Traversal
Introduction The global cybersecurity community witnessed a significant shift in threat metrics when a severe, unauthenticated security flaw within WordPress Core was disclosed. Designated as CVE-2026-87902, this critical flaw impacts tens of millions of active web applications dependent on the open-source Content Management System (CMS). Assigning it a CVSS v4.0 rating of 9.2 (Critical), security threat intelligence teams flagged the vulnerability for its