WordPress Core bug added to US exploited-flaws list — but nobody's saying what it actually does

CISA says CVE-2026-87902 is being actively exploited against WordPress Core, yet the public record is oddly thin on how, who's affected, or whether a fix even exists.

A vulnerability in WordPress Core, tracked as CVE-2026-87902, has been added to the US Cybersecurity and Infrastructure Security Agency’s Known Exploited Vulnerabilities (KEV) catalogue, meaning CISA has evidence it’s being actively used by attackers — not just a theoretical risk sitting in a lab report. WordPress runs a huge chunk of the web, so “actively exploited” is a phrase worth taking seriously. But the actual detail on offer here is remarkably sparse, and that’s the catch.

What’s actually known

CISA’s listing confirms a handful of hard facts: the flaw was added to the KEV catalogue on 25 September 2026, it affects “WordPress Core” (the base software, not a specific plugin or theme), and US federal civilian agencies have been given until 28 September 2026 to apply mitigations under CISA’s binding directive on prioritising security updates. CISA also states explicitly that exploitation is confirmed, not hypothetical.

That’s genuinely useful — it tells us this isn’t a researcher’s proof-of-concept gathering dust, but something attackers are using right now against real sites.

What’s missing — and it’s a lot

Here’s where scepticism earns its keep. Neither CISA’s catalogue entry nor the NVD page for CVE-2026-87902 provided to us spells out what the vulnerability actually does — whether it’s a remote code execution bug, an authentication bypass, a privilege escalation issue, or something else entirely. There’s no CVSS severity score quoted, no list of affected WordPress versions, and no confirmation that a patched version has even been released.

The entry also lists “ransomware: Unknown”, which is CISA’s own way of saying it has no evidence (yet) that ransomware gangs are using this flaw — not that they definitely aren’t. It’s a gap in knowledge, not a clean bill of health.

Without a description of the bug’s mechanics or a confirmed patch version, anyone running WordPress genuinely can’t tell today whether their specific setup is exposed. That’s an unusual amount of silence for a flaw urgent enough to warrant a three-day federal patching deadline.

So who is actually at risk

The short answer: unclear, but potentially a very large number of sites. WordPress Core underpins a sizeable share of websites worldwide, from hobbyist blogs to major commercial platforms, so a Core-level bug (rather than one buried in a niche plugin) has a wide potential blast radius. The federal deadline applies specifically to US government agencies required to comply with CISA’s directives — it doesn’t mean ordinary WordPress site owners have a legal deadline, but it’s a strong signal that the underlying issue is considered serious.

If you don’t run a WordPress site yourself, this doesn’t touch you directly. If you administer one — personally or for a business — you’re the audience that should be paying attention, even with the technical blanks still unfilled.

What to do about it

Until WordPress or a trusted security researcher publishes specifics, the sensible move is the boring one: make sure WordPress Core, plugins and themes are fully up to date, since official fixes for actively exploited flaws tend to land fast once the vendor is aware. Keep an eye on the NVD entry and the CISA KEV catalogue for updates, as both are likely to be filled in with more detail in the coming days.

For now, treat this as a confirmed but under-documented threat: real enough that CISA is forcing US agencies to act within 72 hours, but not yet detailed enough for the rest of us to know precisely what we’re defending against. Patch promptly, watch for updates, and don’t panic on thin information.

Sources