← All articles Security

CVE-2026-87902: The WordPress Flaw Most Owners Missed

A severity score of 9.2 out of 10. Every version of WordPress released since 2016 affected. Active exploitation confirmed within 24 hours of public

Published Jason Boyd

A severity score of 9.2 out of 10. Every version of WordPress released since 2016 affected. Active exploitation confirmed within 24 hours of public disclosure, and no login required. CVE-2026-87902 is the kind of vulnerability that should have been front-page news for every business owner running a WordPress site. For most, it passed without a word.

That gap between what happened and what most business owners knew about it is the real problem.

The technical details of the flaw matter less to you than the operational reality it exposed. A near-perfect severity rating from the security research community means attackers need a script and a list of targets, not sophistication. WordPress powers a substantial share of the web, which means that list is very long, and your site is almost certainly on it. The 24-hour window between public disclosure and active exploitation is the pattern now, not the exception: the moment a vulnerability is published, automated tools begin scanning for unpatched installations. Waiting to see if anyone notices is not a strategy.

The specific risk CVE-2026-87902 carries is that an attacker can interact with your site without holding any kind of account. No subscriber login, no editor credentials, no access of any kind. That removes the most common layer of friction that slows opportunistic attacks, which means your site’s exposure begins the moment the flaw is known publicly and ends only when the patch is applied and verified.

The Window Between Disclosure and Exploitation Is Now Measured in Hours

Security research has tracked this pattern for years, and the trend runs in one direction. The time between a vulnerability being disclosed and the first confirmed exploitation attempts has shortened consistently. A decade ago, businesses could reasonably expect days or weeks to respond — that assumption is now dangerous. For CVE-2026-87902, exploitation began within a single day of the disclosure becoming public.

For a business running WordPress without active monitoring, that window is effectively zero. If no one is watching your site, reading security bulletins, and applying patches as they are released, your site sits exposed for however long it takes you to notice something is wrong. By that point, the question is what attackers found when they accessed your site, because attempts at that severity level are a given.

The consequences of a successful exploit here are specific. Depending on how an attacker uses the access, outcomes include full administrative control of your WordPress installation, theft of customer data stored in your database, injection of malicious code that redirects your visitors to harmful sites, and your domain being flagged by Google as dangerous, which removes you from search results entirely. Each of those outcomes carries a direct commercial cost. Some carry regulatory consequences if customer data is involved.

Self-managed WordPress hosting creates a particular accountability gap. Most business owners who manage their own WordPress site, or rely on a hosting provider’s auto-update feature, have no real visibility into whether a patch has been applied correctly, whether the update introduced a conflict with another plugin, or whether the site is behaving as expected after the change. Auto-updates are better than nothing, but they are not a monitoring strategy.

CVE-2026-87902 Affected Sites Running Versions Released Before Most of Your Staff Joined the Company

Every version of WordPress since 2016 was affected — a decade of releases. The flaw was present in the codebase for years before anyone identified and disclosed it, which means it was not introduced by a recent update. Sites that had not updated recently were exposed. Sites that had been updated were exposed until the specific patch addressing CVE-2026-87902 was applied. The version number alone told you nothing.

This is why version management and patch management are different things. Knowing your site runs WordPress 6.5 does not tell you whether CVE-2026-87902 has been addressed. That requires someone who knows what they are looking for to check, confirm, and document it.

For businesses with any kind of transactional activity on their site, whether that is WooCommerce orders, lead capture forms, membership accounts, or booking systems, the data at risk is concrete: order history, customer addresses, payment references, and account credentials. An attacker with administrative access to a WooCommerce installation can export your entire customer database from the WooCommerce Orders screen in a matter of minutes. That data does not come back once it has left your server.

The question most business owners have not asked themselves is who, specifically, is responsible for knowing about vulnerabilities like CVE-2026-87902 and acting on them within hours of disclosure. “My hosting provider’s auto-update system” or “I check occasionally” are not answers that hold up when something goes wrong. Hosting providers carry no liability for the consequences of a breach on your site. The accountability sits with you.

Professional, active management of a WordPress site means someone is reading the security disclosures, applying patches with urgency when severity warrants it, verifying the site is functioning correctly after each change, and maintaining a documented record of what was done and when. CVE-2026-87902 made visible what was already true: passive site management is a commercial risk, not a cost saving. That is the standard a business with a meaningful online presence should be holding itself to.


If CVE-2026-87902 caught you off guard and you are not certain your site was patched before exploitation attempts began, I offer a WordPress security audit at The WordPress Guy that identifies your current patch status, checks for indicators of compromise, and documents any configuration gaps that leave you exposed. Given that exploitation of this vulnerability began within 24 hours of disclosure, every additional day without a verified patch status is a day your site’s exposure remains unconfirmed. Book a security audit and I will tell you exactly where you stand.

Related articles

All articles →

Security issues need permanent fixes, not surface-level patches. This is exactly the work I specialise in.

View security services →
Jason Boyd

Jason Boyd

Specialist WordPress Engineer · Former W3C Invited Expert · 20+ years

I fix the WordPress problems other developers walk away from. Backed by a 1st Class degree in Computer Science, an MSc in Cybersecurity, and over 20 years of specialist WordPress work, I diagnose issues at their root cause and resolve them permanently, for businesses that cannot afford guesswork or repeat failures.

Need hands-on help?

If this article describes your situation, I can diagnose the specifics and fix it properly. Send your brief and I'll respond the same working day.